logo

Coordinated GitHub API enumeration and access token abuse

ID: 8303321b-0d5d-5fef-a3f7-0314ae24567a

STIX ID: report--8303321b-0d5d-5fef-a3f7-0314ae24567a

Feed Name: Datadog Security Labs

Threat Score
65/100

Date Published: 2026-07-08

Date Updated: 2026-07-23

...
...

Datadog Security Research observed sustained, coordinated abuse of the GitHub API where networks of long-dormant 'ghost' accounts and stolen OAuth/PAT tokens systematically enumerated organizations, users, and repositories (primarily via /graphql and other public endpoints); while most activity was reconnaissance of public data, the campaign included attempts to access private repo commit paths and at least one confirmed private-repo clone. The report provides lists of suspicious user agents and hosting providers, targeted API routes, example actor naming patterns, and Datadog hunting queries to detect programmatic access to private resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.