Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Datadog Security Labs has warned of several overlapping campaigns that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. The campaigns employ a mix of automated scanner tools, over 50 dormant accounts, a…
Intelligence analysis by Llama

Datadog Security Labs has identified several overlapping campaigns that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. The campaigns use a mix of automated scanner tools, dormant accounts, and compromised personal access tokens (PATs) to facilitate the enumeration.
Imagine you have a big library with many books, and someone is using a special tool to scan all the books on the shelves. They're not taking any books, just looking at the titles and authors. This is kind of like what's happening with the GitHub accounts. Someone is using a tool to scan all the accounts and look at the information, but they're not taking anything. It's like a big digital scavenger hunt.
Analysis
A Strategic Approach to Enumeration
The campaigns identified by Datadog Security Labs employ a strategic approach to enumeration, using a mix of automated scanner tools, dormant accounts, and compromised personal access tokens (PATs) to facilitate the enumeration. This approach is designed to avoid raising any red flags and pass off the activity as legitimate, as opposed to creating new accounts and immediately using them for scraping.
The Role of Dormant Accounts
The use of dormant accounts is a key aspect of the campaigns identified by Datadog Security Labs. These accounts were created two to five years ago and intentionally left inactive for extended periods of time before being weaponized to issue API traffic across multiple organizations. This technique is strategic because it aims to avoid raising any red flags and pass off the activity as legitimate.
The Concern Lies in the Aggregate
While individually, most of the requests made by the campaigns are unremarkable, the concern lies in the aggregate. A group of accounts moving in sync across companies' GitHub organizations with versioned custom tooling iterating over weeks, and in the worst case, actors that stopped enumerating and started cloning. This highlights the potential risks of dormant GitHub accounts being used to facilitate malicious activities, such as enumerating corporate GitHub organizations, repositories, and user accounts.
Key points
- Datadog Security Labs has identified several overlapping campaigns that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API.
- The campaigns use a mix of automated scanner tools, dormant accounts, and compromised personal access tokens (PATs) to facilitate the enumeration.
- The use of dormant accounts is a key aspect of the campaigns, with accounts created two to five years ago and intentionally left inactive for extended periods of time before being weaponized.
- The concern lies in the aggregate, with a group of accounts moving in sync across companies' GitHub organizations with versioned custom tooling iterating over weeks.
If the GitHub community and security teams work together to identify and mitigate the risks associated with dormant accounts, it's possible to prevent these types of campaigns from succeeding. Additionally, the use of more secure authentication methods and better monitoring of API activity could help to prevent these types of attacks.
The use of dormant accounts and compromised personal access tokens (PATs) to facilitate malicious activities is a significant concern. If left unchecked, it's possible that these types of campaigns could lead to more severe consequences, such as data breaches or unauthorized access to sensitive information.



