logo

Coordinated GitHub API Enumeration and Access Token Abuse (Campaign)

ID: ddf52e15-7a9c-5ee3-bbaa-e5e7ebdf1e42

STIX ID: report--ddf52e15-7a9c-5ee3-bbaa-e5e7ebdf1e42

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2026-07-08

Date Updated: 2026-07-19

Author: [email protected] (Wiz Threat Research)

...
...

Datadog Security Labs identified multiple coordinated campaigns abusing GitHub APIs and legitimate credentials (including dormant 'ghost' accounts and valid PATs/OAuth tokens) to systematically enumerate organizations, repositories, users, and development activity at scale; although much of the activity focused on public-repo reconnaissance, some cases of compromised credentials allowed unauthorized access to private repositories, increasing supply-chain and intelligence-gathering risk on GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.