HomeSecurityGitHub API abuse: 50+ ghost accounts map organizations in massive recon campaign

GitHub API abuse: 50+ ghost accounts map organizations in massive recon campaign

New extensive research from Datadog Security Labs reveals a sophisticated GitHub API abuse by over 50 ghost accounts — profiles that were created two to five years ago, remained dormant, and were recently activated to mass-collect information from organizations on GitHub.

The campaign, tracked since October 2025, exploits a fundamental design choice of the platform: a huge portion of the GitHub API is accessible without authentication. Attackers enumerate organizations, members, repositories, gists, and follow graphs, mapping entire company ecosystems before triggering more targeted activity.

How the GitHub API abuse of ghost accounts works

Ghost accounts are not newly created profiles that an anti-abuse system would easily detect. They are regular accounts with years of history, which attackers either created proactively or purchased from corresponding marketplaces. When activated, they run bursts lasting 1 to 3 weeks, sending queries to dozens of organizations before going silent again.

GitHub API abuse ghost accounts dormant profiles enumeration

The heavy object of the requests is done through the GraphQL endpoint, which allows bulk queries for dozens of objects in a single call. At the same time, ghost accounts hit REST routes such as /organizations/:id/repos, /user/:id/followers, /user/:id/orgs, /user/:id/starred , and /user/:id/gists. All of these return HTTP 200 responses without any authentication failure signal, making the activity indistinguishable from legitimate traffic.

User agents and tools used by attackers

Datadog has documented over 25 unique user agents used by ghost accounts. Some have names that sound technical but are not legitimate tools: GitHub-Commit-Fetcher, GitHub-Event-Fetcher, gha-injection-scanner, GitHub-Repo-Crawler. Others mimic analytics or dashboard tools with convincing names like GitHubAnalytics, GitHubDashboard, RepoAnalyzer, GitHub-Insights , and GitHubMetrics.

The open-source tool GitHarvester also appears in the IoCs, along with hosting providers such as cherryservers and 3xktech that have been used to source the requests. Notably, the activity is not attributed to a single perpetrator — Datadog describes a mix of custom automated scanners, opportunistic abuse of leaked credentials, and coordinated networks of burner ghost accounts.

GitHub API abuse compromised tokens private repositories exfiltration attack

From recon to theft: parallel campaign with compromised tokens

Alongside the ghost accounts, a second campaign observed in December 2025 and January 2026 used dozens of compromised OAuth access tokens and Personal Access Tokens from legitimate users. Unlike the more infamous GitHub API abuse of ghost accounts, this attack was much more aggressive: within minutes, hundreds of requests were made to a target, including git.clone, repo.download_zip , and direct API requests to private repositories.

In a confirmed case, attackers were able to download the full contents of a private repository from a target by exploiting tokens leaked in public commits or CI/CD tools. The user agent versions recorded (GitHub-Commit-Fetcher/1.3 → 1.4 → GitHub-Event-Fetcher/2.2) indicate active tooling development during the attack.

Why GitHub API abuse is so hard to detect

Datadog's key finding is that traditional defense methods fail here. Because enumeration targets public data, all requests return HTTP 200 responses, with no rate-limit alerts, no authentication failures, and no unusual error codes. The only real difference from legitimate traffic is the user agent and pattern, which require deeper audit log analysis.

GitHub audit log user agent detection GraphQL enumeration monitoring

Worse, reconnaissance usually precedes targeted attacks. An attacker who already knows which projects are touched by which engineer, which external dependencies are running, and who has privileges in which repositories, can precisely target their next move — from supply-chain attacks to social engineering.

How to protect yourself from GitHub API abuse

The SecNews technical team recommends the following steps for any organization with a presence on GitHub:

  • Enabling GitHub audit log streaming in a SIEM or security lake — essential for every enterprise plan.
  • Baselining legitimate user agents reaching the organization's endpoints — create an allowlist.
  • Detection queries for successful accesses to private repositories by unusual user agents or suspicious PATs.
  • Periodic audit of Personal Access Tokens and OAuth apps — look for old, unusual scopes or unused tokens.
  • Rotation of tokens exposed in public commits (using tools like gitleaks and trufflehog).
  • Enable fine-grained PATs instead of classic ones, with explicit repository and permission scopes.

It is particularly critical for the security team to do proactive threat hunting: instead of waiting for alerts, look for user agents like GitHubAnalytics, RepoAnalyzer, GitHub-Monitor , and all the others that Datadog has recorded as IoCs.

What GitHub API abuse means for the broader DevSecOps ecosystem

The revelation confirms a truth that more and more research groups are emphasizing: GitHub has become the most critical supply-chain attack surface in any modern software organization. Reconnaissance via API abuse can map an organization in more detail than OSINT tools, uncover internal relationships and dependencies, and pave the way for targeted malware, phishing, or compromise engineer accounts.

The SecNews editorial team urges any organization that prioritizes cloud-native and DevSecOps practices to treat the GitHub audit log with the same seriousness as it treats AWS CloudTrail or Azure Activity Log.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: GitHub Agentic Workflows: Critical prompt injection vulnerability

See also: HalluSquatting: New supply-chain attack on AI-generated packages

See also: Ghostcommit: Prompt injection in images steals secrets from AI agents

Source: Datadog Security Labs — Coordinated GitHub API enumeration and access token abuse

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS