Wiz CIRT reported a coordinated campaign in which threat actors used compromised GitHub Personal Access Tokens (PATs) to reconnoiter and exfiltrate private repositories from multiple organizations. Activity began with repository enumeration on May 15, followed by low-volume clone validation between May 29 and May 31, before highly parallel cloning on June 1. The attackers used 102 IP addresses in AWS's ca-central-1 region and the git/2.43.0 user agent, cloning as many as thousands of repositories from individual victims.
The origin of the stolen PATs remains unknown. Wiz found no evidence that the tokens had been exposed in source code or cloud resources, while endpoint credential theft remains a possible access vector. Organizations should revoke and rotate affected PATs and credentials, identify every repository cloned with compromised accounts, assess exposed secrets, and hunt across cloud and SaaS environments for follow-on abuse of harvested access material.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
From approximately 09:14 to 14:55 UTC, the actors used 102 AWS ca-central-1 IP addresses and the git/2.43.0 user agent to highly parallelize cloning of private repositories. The campaign exfiltrated up to thousands of repositories per affected organization.
A threat actor used compromised GitHub Personal Access Tokens to query the /repositories/{id}/readme API endpoint from 13.221.167.217, an EC2 IP in AWS us-east-1. The activity generated GitHub api.request events and used a Chrome 125 user agent.
Between May 29 and May 31, compromised PATs performed a limited number of git.clone operations from 107.174.201.183, attributed to HostPapa in the United States. The near-simultaneous activity across victims and git/2.25.1 user agent indicated automated validation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 104 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.