UNC6426UNC6426

Also known as: UNC6426

Known aliases
1

Profile

UNC6426 exploited a supply chain compromise of the nx npm package to steal a developer's GitHub Personal Access Token and gain access to a victim's cloud environment. They abused the GitHub-to-AWS OpenID Connect trust to create a new administrator role, leveraging overly permissive permissions associated with the compromised GitHub-Actions-CloudFormation role. Using the legitimate open-source tool Nord Stream, UNC6426 conducted reconnaissance and extracted secrets from CI/CD environments, leading to the exfiltration of files from AWS S3 buckets and data destruction. The actor escalated to full AWS administrator permissions in under 72 hours.

Aliases· 1

UNC6426

References

  1. https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UNC6395
Actor
UNC2465
Actor
UNC6671
Actor
UNC6485
Actor
UNC6692
Actor
UNC2659
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.