Threat actors are systematically abusing the GitHub API to enumerate organizations, repositories, and user accounts in a mass reconnaissance campaign that has been active for several months, relying on a network of ghost accounts registered two to five years ago and left dormant until now. The coordinated activity, detailed by Datadog, involves automated scanners, the exploitation of leaked credentials, and these pre-established dormant accounts to map out the digital infrastructure of targeted entities.
How the GitHub API Reconnaissance Campaign Operates
The observed activity targets publicly available data through legitimate GitHub API endpoints, allowing the malicious traffic to blend seamlessly with normal, everyday API requests. A large share of GitHub’s API does not require authentication to access public information. Attackers can list an organization’s public repositories, walk a user’s follower and following lists, enumerate gists, starred repos, and organization memberships, and run GraphQL queries against public objects—all without triggering authentication failures.
Datadog explains that requests against these public paths generate standard HTTP 200 responses and no authentication error signals. This allows an operator to use normal API traffic to map an organization, its members, and the projects they access, building a detailed picture of the target’s digital footprint.
Dormant Accounts and Rogue User Agents
Since at least October 2025, more than 50 ghost accounts have been used to send API traffic as part of the enumeration. These accounts are typically active in bursts lasting 1 to 3 weeks, targeting multiple organizations. The accounts employ user agents designed to sound like legitimate data exfiltration, analytics, or dashboard tools to further evade detection. The majority of requests target GraphQL endpoints, with a smaller portion aimed at REST routes.
“On its own, this enumeration rarely produces meaningful access inside an organization, rather it’s accomplishing reconnaissance,” Datadog notes.
Escalation Beyond Reconnaissance: Token Abuse and Data Exfiltration
In one specific campaign, attackers were observed using inadvertently exposed tokens from legitimate GitHub users. They targeted private repository commit paths from dozens of legitimate accounts over a window of several minutes. In rare but significant cases, the attackers moved beyond reconnaissance and successfully exfiltrated data from targeted organizations, Datadog states.
Detecting and Defending Against GitHub API Reconnaissance Campaigns
For defenders looking to identify this type of malicious activity, the key lies in monitoring for anomalous behavior. Security teams should check logs for data exfiltration from private repositories and watch for unusual user agent behavior, particularly in the naming and versioning of user agents used in actions reaching private repositories.
“User agents, event activity, and actor names are vital clues to unauthorized activity in your environment. It’s important to know what normal looks like in your environment,” Datadog advises. The firm recommends enabling GitHub audit log streaming, baselining user agents, proactively threat hunting, and developing detections unique to your GitHub organization.
Why This Matters for Organizations Using GitHub
This campaign highlights a significant blind spot in many organizations’ security postures. The abuse of legitimate, public APIs for reconnaissance is a low-and-slow technique that can go unnoticed for extended periods. While the primary goal is information gathering, the potential for escalation to data theft makes this a serious concern. The use of pre-aged, dormant accounts demonstrates a sophisticated level of operational security by the threat actors, making account age alone an unreliable indicator of trust.
What Affected Organizations Should Do Now
Organizations that use GitHub should immediately take concrete steps to improve their security posture against this type of threat. The most critical action is to enable GitHub audit log streaming to a dedicated security information and event management (SIEM) system. This provides a centralized, searchable record of all API activity. Secondly, security teams must establish a baseline of normal user agent behavior for their organization and implement detections for any deviations. Proactive threat hunting for patterns consistent with API enumeration—such as rapid, sequential requests to public repository, member, and follower endpoints—should become a regular part of the security operations cadence. Finally, any exposed or leaked credentials should be immediately rotated and the use of fine-grained personal access tokens with minimal permissions should be enforced to limit the blast radius of any future token abuse.