Unc6426 — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
March 11, 2026
Last Seen
May 13, 2026

Unc6426 is a apt_group tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed March 11, 2026; most recent activity May 13, 2026.

Related Threat Clusters

  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    690 articles · Updated April 29, 2026
  • UNC6426 Exploits npm Supply Chain for AWS Admin Access

    Hackers identified as UNC6426 have exploited vulnerabilities in the npm supply chain, specifically targeting the nx package, to gain AWS admin access within 72 hours. This incident raises significant concerns for…

    3 articles · Updated March 11, 2026

Recent Intelligence Reports

  • Trusted by default: The npm attack pattern security teams miss | perspective — Scworld · May 13, 2026
  • UNC6426 Hackers Exploit NPM Package to Gain AWS Admin Access in 72 Hours — Gbhackers · March 11, 2026

CVSS v3.1 Breakdown