hacker-news · Crawled Jul 9, 2026

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

1 IoCs
Read original article ↗

AI Summary

Multiple overlapping campaigns are actively enumerating corporate GitHub organizations, repositories, and user accounts using automated scraping tools and compromised or dormant GitHub accounts. Attackers leverage old 'ghost' accounts and exposed personal access tokens (PATs) to blend in with legitimate traffic and avoid detection while conducting reconnaissance. The activity includes querying public endpoints to map organizational structures and, in some cases, cloning private repositories. This behavior enables threat actors to gather intelligence for potential supply chain attacks.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
GitHub User ghost Details →