UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours
ID: 446f2643-8769-58a5-b873-aaa20866fd04
STIX ID: report--446f2643-8769-58a5-b873-aaa20866fd04
Feed Name: The Hacker News
Google's Cloud Threat Horizons report details a rapid supply-chain and cloud compromise by UNC6426: a trojanized nx npm package executed a JavaScript credential stealer (QUIETVAULT) that harvested GitHub tokens and secrets, enabling the actor to abuse GitHub-to-AWS OIDC trust to create an AdministratorAccess role, escalate to full AWS admin within 72 hours, exfiltrate S3 data, destroy EC2/RDS instances, and expose internal repositories; the incident highlights AI-assisted supply-chain abuse and recommends PoLP, fine-grained PATs, sandboxing postinstall actions, and monitoring for anomalous IAM activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
