ai hardware Intelligence
UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours
May 16, 2026
Hype Score: 90
2 Sources
Executive Summary
Threat actor UNC6426 leveraged stolen keys from the nx npm package supply chain compromise to breach a victim's cloud environment within 72 hours — stealing a GitHub token, abusing OIDC trust to create AWS admin roles, and exfiltrating S3 data.
📊 Market Strategic Impact
Highest-impact npm supply chain attack documented: compromised build tool → stolen GitHub token → AWS admin → production data destruction in 72 hours.
UNC6426: From npm Supply Chain to AWS Admin in 72 Hours
The Full Story
The nx supply chain attack received modest attention when first disclosed. A threat actor exploited a vulnerable pull_request_target GitHub Actions workflow to inject malicious code. What wasn't known was how far the downstream impact would reach.The Attack Chain
Stage 1: Attacker gained access to a developer's GitHub PAT via compromised nx package. Stage 2: Mapped victim org's repos and CI/CD, identified GitHub Actions with OIDC trust to AWS. Stage 3: Abused GitHub-to-AWS OIDC trust to create a new administrator IAM role. Stage 4: Enumerated and exfiltrated S3 buckets (customer databases, configs). Stage 5: Performed data destruction in production cloud environments.So What? — Market Impact
For platform engineers: Audit your GitHub-to-AWS OIDC trust configurations immediately. Apply condition constraints limiting which repos/branches can assume IAM roles. For the npm ecosystem: This is the highest-impact npm supply chain attack documented to date.Sources
Community Sentiment
--%
0 votes · 0 up · 0 down