Coordinated GitHub API enumeration and access token abuse
ID: 8303321b-0d5d-5fef-a3f7-0314ae24567a
STIX ID: report--8303321b-0d5d-5fef-a3f7-0314ae24567a
Feed Name: Datadog Security Labs
Datadog Security Research observed sustained, coordinated abuse of the GitHub API where networks of long-dormant 'ghost' accounts and stolen OAuth/PAT tokens systematically enumerated organizations, users, and repositories (primarily via /graphql and other public endpoints); while most activity was reconnaissance of public data, the campaign included attempts to access private repo commit paths and at least one confirmed private-repo clone. The report provides lists of suspicious user agents and hosting providers, targeted API routes, example actor naming patterns, and Datadog hunting queries to detect programmatic access to private resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
