UNC6426 is a threat cluster tracked for a rapid follow-on intrusion that weaponized credentials stolen during the August 2025 supply-chain compromise of the nx npm package ecosystem. The actor used a stolen developer GitHub token to pivot from a compromised software development environment into a victim’s Amazon Web Services environment in less than 72 hours, demonstrating a fast transition from supply-chain access to cloud compromise. The intrusion chain involved abuse of a GitHub-to-AWS OpenID Connect trust relationship to obtain cloud access, followed by privilege escalation through creation of a new administrator role. With elevated permissions, UNC6426 conducted reconnaissance in the victim’s GitHub and cloud environments, extracted additional CI/CD secrets, accessed and exfiltrated data from cloud storage, and carried out destructive actions in production infrastructure. Reported post-compromise activity included administrative role creation, cloud resource abuse, data exfiltration, and data destruction. UNC6426’s tradecraft reflects a modern developer-centric intrusion model in which compromised developer credentials and CI/CD trust relationships are used as the bridge into production cloud environments. High-confidence behaviors associated with the actor include initial access through stolen credentials, reconnaissance, privilege escalation, exfiltration, and post-exploitation in cloud environments. Public reporting does not provide high-confidence attribution of UNC6426 to a specific country or broader named intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Follow-on operation that leveraged stolen GitHub tokens from the NX compromise to breach a victim AWS environment rapidly.
Leveraged credentials stolen via the trojanized nx npm package supply-chain compromise to pivot from GitHub into AWS by abusing GitHub-to-AWS OIDC trust, creating new IAM administrator roles, exfiltrating S3 data, and performing destructive actions (terminating EC2/RDS, renaming and publishing internal GitHub repos).
Exploited access obtained from the nx npm supply-chain compromise to steal a developer's GitHub token, abuse GitHub-to-AWS OIDC trust, create a new AWS administrator role, exfiltrate data from S3 buckets, and perform destructive actions in the victim's production cloud environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.