Old, Silent GitHub Accounts Are Being Used to Quietly Map Companies
Datadog Security Labs says several overlapping scraping campaigns are cataloguing corporate GitHub organisations using dormant 'ghost' accounts and stolen tokens.

Key points
- Datadog Security Labs reported in November 2025 that several overlapping campaigns are systematically scraping corporate GitHub organisations, repositories, and user accounts.
- Operators use automated tools that mimic normal web traffic, running through GitHub 'ghost' accounts that are often years old.
- Some campaigns also run on stolen OAuth tokens and personal access tokens taken from real developers.
- The activity is reconnaissance: the attackers are mapping targets rather than breaking in, at least for now.
- Companies are being advised to audit which accounts and apps can read their GitHub organisation data.
Someone is quietly taking inventory of corporate code.
Researchers at Datadog Security Labs say they've spotted several overlapping campaigns crawling GitHub, the code-hosting site used by most of the world's software companies. The campaigns pull organisation lists, user accounts and repository names through GitHub's API, the machine-to-machine interface that lets software query the site automatically. First reported by The Hacker News, the finding builds on what Datadog was already tracking: we covered an earlier wave of this automated GitHub snooping on 8 July.
This is reconnaissance, not a break-in. The attackers are building a map: who works where, which company owns which project, which repositories exist. That index is valuable for phishing, where criminals send fake emails to trick staff into surrendering passwords, and for targeted attacks on the software supply chain.
Who is doing this?
Datadog hasn't named a single group, and that's the point. Its researchers describe "several overlapping campaigns," suggesting more than one operator is running similar playbooks simultaneously. Some look like criminal crews doing pre-attack homework; others could be data brokers. The tooling overlaps enough that telling them apart is hard.
What they share is a way of hiding in plain sight.
How are they staying hidden?
Three mechanisms, mainly.
First, the scrapers impersonate normal software. They set a user agent, the label a program sends to identify itself, to something bland. Nothing flags them as scrapers.
Second, they log in as ghosts: GitHub accounts created years ago and left dormant. No code, no followers, no obvious purpose. Age makes an account look legitimate to automated defences. Some were probably created in bulk long before this campaign started.
Third, and more worrying, some campaigns run on stolen credentials. Datadog says operators are using compromised OAuth tokens and personal access tokens, the digital keys developers generate to let apps or scripts act on their behalf. A leaked token gives whoever holds it the same read access the original developer had, including private company repositories. A clickjack-style flaw in github.dev exposed exactly these kinds of tokens to theft in June, which illustrates how the supply of stolen tokens keeps refreshing.
Should ordinary companies worry?
Yes, but calmly.
If your organisation uses GitHub, someone may already hold a list of your repositories and staff usernames. That's not a breach on its own. It becomes dangerous when the list feeds convincing phishing emails to your developers, or helps an attacker hunt for a leaked credential that unlocks a real repository.
The practical response is unglamorous. Review which OAuth apps have access to your GitHub organisation. Rotate personal access tokens, especially long-lived ones. Require two-factor authentication across the org. Watch for API traffic from accounts with no meaningful history.
For individual developers: treat every token you generate like a house key. Give it the shortest life and fewest permissions you can, and delete it the moment you no longer need it.
The scraping itself is quiet work. What follows it won't be.



