{"id":222255,"date":"2026-03-11T03:31:00","date_gmt":"2026-03-11T07:31:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/03\/11\/unc6426-exploits-nx-npm-supply-chain-attack-to-gain-aws-admin-access-in-72-hours\/"},"modified":"2026-03-11T05:10:12","modified_gmt":"2026-03-11T09:10:12","slug":"unc6426-exploits-nx-npm-supply-chain-attack-to-gain-aws-admin-access-in-72-hours","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/03\/11\/unc6426-exploits-nx-npm-supply-chain-attack-to-gain-aws-admin-access-in-72-hours\/","title":{"rendered":"UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/unc6426-exploits-nx-npm-supply-chain.html\">UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/unc6426-exploits-nx-npm-supply-chain.html\">https:\/\/thehackernews.com\/2026\/03\/unc6426-exploits-nx-npm-supply-chain.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-03-11 03:31:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Mar 11, 2026<\/span><\/span><span class=\"p-tags\">DevSecOps \/ AI Security<\/span><\/p>\n<p>A threat actor known as <strong>UNC6426<\/strong> leveraged keys stolen following the supply chain compromise of the nx npm package last year to completely breach a victim&#8217;s cloud environment within a span of 72 hours.<\/p>\n<p>The attack started with the theft of a developer&#8217;s GitHub token, which the threat actor then used to gain unauthorized access to the cloud and steal data.<\/p>\n<p>&#8220;The threat actor, UNC6426, then used this access to abuse the GitHub-to-AWS OpenID Connect (OIDC) trust and create a new administrator role in the cloud environment,&#8221; Google said in its Cloud Threat Horizons Report for H1 2026. &#8220;They abused this role to exfiltrate files from the client&#8217;s Amazon Web Services (AWS) Simple Storage Service (S3) buckets and performed data destruction in their production cloud environments.&#8221;<\/p>\n<p>The supply chain attack targeting the nx npm package took place in August 2025, when unknown threat actors exploited a vulnerable pull_request_target workflow \u2013 an attack type referred to as Pwn Request \u2013 to obtain elevated privileges and access sensitive data, including a GITHUB_TOKEN, and ultimately push trojanized versions of the package to the npm registry.<\/p>\n<p>The packages were found to embed a postinstall script that, in turn, launched a JavaScript credential stealer named QUIETVAULT to siphon environment variables, system information, and valuable tokens, including GitHub Personal Access Tokens (PATs), by weaponizing a Large Language Model (LLM) tool already installed on the endpoint to perform the search. The data was uploaded to a public GitHub repository named &#8220;\/s1ngularity-repository-1.&#8221;<\/p>\n<p>Google said an employee at the victim organization ran a code editor application that used the Nx Console plugin, triggering an update in the process and resulting in the execution of QUIETVAULT.<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"1341\" data-original-width=\"2592\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjEfFFJ_wrDq-3ihTfkE37VoFS7HH4cGqZfyqSfpWwj4Kk6C_q547nkuIzdkQZEyOQEDhnMSEPx7ZSYQSbCQOCPh2mhdznCGJayi0Xp2bT2ike2Tdx1_dEUKQqehEXAo9DLCEDUFDb4WtJNsT7WXGrD6BwzF6feQ3yJzWw2RH4vLsGnwqw3AOj3gGDY5d9D\/s1600\/google.jpg\"\/><\/p>\n<p>UNC6426 is said to have initiated reconnaissance activities within the client&#8217;s GitHub environment using the stolen PAT two days after the initial&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/unc6426-exploits-nx-npm-supply-chain.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours https:\/\/thehackernews.com\/2026\/03\/unc6426-exploits-nx-npm-supply-chain.html&#8230;<\/p>\n","protected":false},"author":1,"featured_media":222256,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjFUREkqLhVFM9jnUqkHPMEmAj2KBdTrXOX_m8t7zEUdK4NE16BBL0XQHZ9q4KPVDfKecgf4KE64vzAW9XDvn6axd6fIU9WZy5Lqe348eT7rKvmsLU3ByDPajxWFlkTt6CQTNkmNv8e57XrvWAaM-YaXtD0QP1-grx4XPtV_Osxw-vjtPfw4A70O5x41yvq\/s1600\/aws.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[26,30,18,17,34],"class_list":["post-222255","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ai","tag-breach","tag-large-language-model","tag-llm","tag-threat-actor"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/222255"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=222255"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/222255\/revisions"}],"predecessor-version":[{"id":222257,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/222255\/revisions\/222257"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/222256"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=222255"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=222255"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=222255"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}