{"id":1685,"date":"2026-07-09T18:48:20","date_gmt":"2026-07-09T18:48:20","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1685"},"modified":"2026-07-09T18:48:20","modified_gmt":"2026-07-09T18:48:20","slug":"dormant-github-accounts-help-attackers-blend-in-while-mapping-corporate-orgs","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1685","title":{"rendered":"Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 09, 2026<\/span><\/span><span class=\"p-tags\">Developer Security \/ Supply Chain Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiDslymdYqhkFwIm3ZeaXVZweYVT_R1d6LCQhIm799y9-5hQ3C45cumIStxGYheFbwosbd_JtrB6FgOthR2KJgfe8PYs0k47eGV7263ATac5UR0t7OOaqOUGOf5DHAR4b0IaKTozk0UEiHJz5-nze3b1ureycPGqdPVlqrImWreOWwMpGxC8kgBvONCLGbH\/s1700-e365\/github-ghost.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Datadog Security Labs is warning of \u00abseveral overlapping campaigns\u00bb that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub\u00a0API.<\/p>\n<p>\u00abOperators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub &#8216;ghost&#8217; accounts that are often years old, or compromised OAuth tokens and personal access tokens (PATs) from legitimate users,\u00bb Julie Agnes Sparks, senior security engineer at Datadog, <a href=\"https:\/\/securitylabs.datadoghq.com\/articles\/coordinated-github-api-enumeration\/\" target=\"_blank\">said<\/a>.<\/p>\n<p>While the activity in most cases involves targeting public data, select instances have gone beyond public information enumeration to successfully clone private repositories.<\/p>\n<p>The campaign employs a mix of automated scanner tools, over 50 dormant accounts, and dozens of legitimate accounts that have had their personal access tokens (PATs) exposed unintentionally or compromised through some other method to facilitate the enumeration.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>What&#8217;s notable about the \u00abghost\u00bb accounts is that they were created two to five years ago and intentionally left inactive for extended periods of time before weaponizing them to issue API traffic across multiple organizations. This technique is strategic as it aims to avoid raising any red flags and pass off the activity as legitimate, as opposed to creating new accounts and immediately using them for scraping.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj-p7tS8EgDedWZ3DHn6JMzEdkr0NzmVNTTWmFRqTvu_1bZdqgH4r_UKic2ka8FSE65yrGbRgqSqGECX7l2_5t9vqYvl2MF8O2_pQfPDXfyZ9GN3uUnWsSilR7Q5ECPxyVmnVdN9hBIiNyGy672WDfEvtNrTnuQpz8UB0AzbeFqmWVtKHTidP6EWYvjOaGa\/s1700-e365\/scrape.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj-p7tS8EgDedWZ3DHn6JMzEdkr0NzmVNTTWmFRqTvu_1bZdqgH4r_UKic2ka8FSE65yrGbRgqSqGECX7l2_5t9vqYvl2MF8O2_pQfPDXfyZ9GN3uUnWsSilR7Q5ECPxyVmnVdN9hBIiNyGy672WDfEvtNrTnuQpz8UB0AzbeFqmWVtKHTidP6EWYvjOaGa\/s1700-e365\/scrape.jpg\" alt=\"\" border=\"0\" data-original-height=\"906\" data-original-width=\"1902\"\/><\/a><\/div>\n<p>Because a large chunk of GitHub&#8217;s API surface is reachable without authentication, the enumeration queries return the necessary data, while blending into normal API usage. Some of them include\u00a0&#8211;<\/p>\n<ul>\n<li>Listing an organization&#8217;s public repositories<\/li>\n<li>Walking a user&#8217;s followers and following lists<\/li>\n<li>Enumerating gists, starred repos, and org memberships,\u00a0and<\/li>\n<li>Running GraphQL queries against public objects<\/li>\n<\/ul>\n<p>This information can be used by a threat actor to conduct reconnaissance and programmatically map out an organization&#8217;s GitHub-related activity, such as its public repositories, its members, who those members follow, and which projects they modify.<\/p>\n<p>Data access has been confirmed in a few scenarios, with the attackers taking steps to clone a private repository belonging to a single organization.<\/p>\n<p>\u00abIndividually, most of these requests are unremarkable. They hit public endpoints, authenticate cleanly or not at all, and return successful responses,\u00bb Datadog said. \u00abThe concern lies in the aggregate: a group of accounts moving in sync across companies&#8217; GitHub organizations with versioned custom tooling iterating over weeks, and in the worst case, actors that stopped enumerating and started cloning.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 09, 2026Developer Security \/ Supply Chain Security Datadog Security Labs is warning of \u00abseveral overlapping campaigns\u00bb that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1686,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[592,622,2445,2447,2194,71,2446,882],"class_list":["post-1685","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-accounts","tag-attackers","tag-blend","tag-corporate","tag-dormant","tag-github","tag-mapping","tag-orgs"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1685","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1685"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1685\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1686"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1685"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1685"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1685"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}