hacker-news · Crawled Jul 9, 2026
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
1 IoCs
Read original article ↗
AI Summary
Multiple overlapping campaigns are actively enumerating corporate GitHub organizations, repositories, and user accounts using automated scraping tools and compromised or dormant GitHub accounts. Attackers leverage old 'ghost' accounts and exposed personal access tokens (PATs) to blend in with legitimate traffic and avoid detection while conducting reconnaissance. The activity includes querying public endpoints to map organizational structures and, in some cases, cloning private repositories. This behavior enables threat actors to gather intelligence for potential supply chain attacks.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| GitHub User | ghost | Details → |