Datadog Security Research reported sustained campaigns abusing GitHub’s public and authenticated APIs to enumerate enterprise organizations, repositories, and users while blending into normal developer traffic. The activity relied on automated scraping through endpoints including /graphql, dormant “ghost” GitHub accounts, and in some cases compromised OAuth tokens or personal access tokens. Researchers identified more than 50 ghost accounts since October 2025, along with recurring user agents such as GitHub-Company-Scraper, GitHub-Scraper-Tool/1.0, GitHubAnalytics/1.5, GitHub-Commit-Fetcher/1.3, GitHub-Commit-Fetcher/1.4, and GitHub-Event-Fetcher/2.2, with some infrastructure linked to 3xK Tech.
While much of the traffic queried public data and appeared benign in isolation, researchers said the aggregate behavior amounted to coordinated reconnaissance that could support later theft of secrets, repository cloning, or broader intrusion activity. In a more serious observed case, a tool identified as repo-dumper successfully cloned or accessed a private repository, with GitHub audit logs showing git.clone and api.request events against private paths. Defenders were urged to baseline GitHub audit activity and hunt for unusual user agents, actor names, token types, source ASNs, and successful access to private resources, while also enforcing MFA, conducting access reviews, enabling audit log streaming, and using repository secret scanning.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
SecurityWeek's summary of Datadog's findings says that in rare cases the GitHub API abuse campaign progressed beyond reconnaissance to successful data exfiltration from targeted organizations. This represents an escalation from the previously documented enumeration and private repository access activity.
Datadog Security Labs published research describing sustained abuse of GitHub public APIs, ghost accounts, and compromised tokens to enumerate enterprise organizations, repositories, and users. The report also recommended hunting in GitHub audit logs for suspicious user agents, actors, token types, ASNs, and private-resource access.
Datadog described a more serious case in which a user agent named repo-dumper successfully cloned or otherwise accessed a private repository. GitHub audit logs showed git.clone and api.request events against private paths, indicating confirmed access to private resources.
In late December 2025 to early January 2026, one campaign used stolen legitimate-user GitHub tokens along with versioned scraper user agents such as GitHub-Commit-Fetcher and GitHub-Event-Fetcher. Datadog linked this activity to infrastructure hosted at 3xK Tech.
Datadog reported observing more than 50 dormant "ghost" GitHub accounts used in coordinated GitHub API enumeration campaigns. The report explicitly anchors these observations as starting in October 2025, with accounts grouped by naming patterns and suspicious scraper user agents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcecysecurity.news
Open sourcethehackernews.com
Open sourcecyberveille.ch
Open sourcesecuritylabs.datadoghq.com
Open sourceinfoworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.