CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2267

As cited

Copy frozen at (site build).

threat intel

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

Datadog Security Labs identified multiple coordinated campaigns systematically enumerating GitHub organizations, repositories, and user accounts via the GitHub API. The attackers use automated scraping tools with legitimate-appearing user agents and leverage dormant ghost accounts or compromised OAuth tokens to avoid detection while conducting reconnaissance.

Why it matters: Any organization with public or private GitHub repositories faces reconnaissance risk from attackers mapping corporate structures and code repositories; security teams should review GitHub API access logs and monitor for unusual enumeration patterns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

Datadog Security Labs identified multiple campaigns using automated tools to enumerate corporate GitHub organizations, repositories, and user accounts via the GitHub application programming interface (API). Attackers employ dormant or ghost accounts that may be years old, as well as compromised OAuth tokens and personal access tokens, to blend reconnaissance activity into normal traffic.

Why it matters: Development teams and security operations centers (SOCs) should audit GitHub organization member access and review API activity logs for signs of enumeration, as reconnaissance precedes initial access attempts and data theft in supply chain attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

Datadog Security Labs identified multiple campaigns using automated tools to enumerate corporate GitHub organizations, repositories, and user accounts via the GitHub application programming interface (API). Attackers employ dormant or ghost accounts that may be years old, as well as compromised OAuth tokens and personal access tokens, to blend reconnaissance activity into normal traffic.

Why it matters: Development teams and security operations centers (SOCs) should audit GitHub organization member access and review API activity logs for signs of enumeration, as reconnaissance precedes initial access attempts and data theft in supply chain attacks.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary