Skip to content

Datadog Warns of Espionage Campaigns via Abandoned GitHub Accounts

In a nutshell: Attackers are exploiting abandoned and compromised GitHub accounts to systematically reconnaissance company structures and in some cases exfiltrate private code repositories.

Datadog Security Labs has identified multiple coordinated campaigns using inactive GitHub accounts and compromised tokens to systematically scout corporate structures and in some cases clone private repositories.

Attackers use automated scraping tools with inconspicuous user credentials, including so-called ghost accounts that have been inactive for two to five years in some cases, as well as compromised OAuth tokens and personal access tokens (PATs) from legitimate users. This strategy aims to circumvent security mechanisms that would block newly registered accounts showing sudden high activity. Since significant parts of the GitHub API are accessible without authentication, the queries blend inconspicuously into normal traffic.

The campaigns collect public repositories, follower lists, gists, organization memberships, and execute GraphQL queries against public objects. In this way, attackers create detailed profiles of a company’s development activities. Individual requests are barely traceable in automated logs, as they use clean authentications or access free endpoints. The threat only becomes visible when coordinated account groups synchronously work through the infrastructure of different companies over weeks.

In selected cases, attackers succeeded in fully cloning private repositories using the gathered data and compromised tokens. This demonstrates that the campaigns do not remain limited to reconnaissance but can incrementally escalate to copying internal source code. For CISOs, this is an indication that GitHub access accounts and tokens should be treated as attack vectors against development infrastructure and intellectual property.


Source: www.it-daily.net · Published July 14, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: