<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/github-api-abuse-ghost-accounts-part-of-malicious-efforts-to-map-organizations-bsffbfs4m" -->

---
title: GitHub API Abuse, ‘Ghost’ Accounts Part of Malicious...
description: Datadog researchers have uncovered coordinated, multi-month campaigns abusing GitHub&#x27;s API and reactivated &#x27;ghost&#x27; accounts to map organizations, their...
canonical: https://daily.dev/posts/github-api-abuse-ghost-accounts-part-of-malicious-efforts-to-map-organizations-bsffbfs4m
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: GitHub API Abuse, ‘Ghost’ Accounts Part of Malicious Efforts to Map Organizations | daily.dev
og:description: Datadog researchers have uncovered coordinated, multi-month campaigns abusing GitHub&#x27;s API and reactivated &#x27;ghost&#x27; accounts to map organizations, their...
og:url: https://daily.dev/posts/github-api-abuse-ghost-accounts-part-of-malicious-efforts-to-map-organizations-bsffbfs4m
og:image: https://api.daily.dev/og/posts/bsffBfS4m.png
og:image:alt: GitHub API Abuse, ‘Ghost’ Accounts Part of Malicious Efforts to Map Organizations
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# GitHub API Abuse, ‘Ghost’ Accounts Part of Malicious Efforts to Map Organizations

**[DevOps.com](https://daily.dev/sources/devops)** · 6 min read · 0 upvotes · 0 comments

## Summary

Datadog researchers have uncovered coordinated, multi-month campaigns abusing GitHub's API and reactivated 'ghost' accounts to map organizations, their developers, and repositories. Most activity exploits public API endpoints — including unauthenticated GraphQL and REST calls — making it nearly indistinguishable from legitimate traffic. Over 50 dormant accounts, inactive for 2–5 years, were reactivated to conduct reconnaissance while appearing trustworthy. Some campaigns went further, using stolen personal access tokens (PATs) to probe private repositories, and at least one case resulted in data exfiltration via Git cloning. Cofense data shows malicious campaigns against Git platforms have grown yearly since 2021, with 95% targeting GitHub. Defenders are advised to enable GitHub audit log streaming, baseline user agents, rotate PATs, and proactively threat hunt for anomalous API patterns.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://devops.com/github-api-abuse-ghost-accounts-part-of-malicious-efforts-to-map-organizations>

## Similar posts on daily.dev

- [GitHub’s public APIs are becoming an enterprise reconnaissance tool](https://daily.dev/posts/github-s-public-apis-are-becoming-an-enterprise-reconnaissance-tool-ty1kvhyvy) · InfoWorld · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#github](https://daily.dev/tags/github), [#data-exfiltration](https://daily.dev/tags/data-exfiltration)

[View this post on daily.dev](https://daily.dev/posts/github-api-abuse-ghost-accounts-part-of-malicious-efforts-to-map-organizations-bsffbfs4m)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"GitHub API Abuse, ‘Ghost’ Accounts Part of Malicious Efforts to Map Organizations","url":"https://daily.dev/posts/github-api-abuse-ghost-accounts-part-of-malicious-efforts-to-map-organizations-bsffbfs4m","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/github-api-abuse-ghost-accounts-part-of-malicious-efforts-to-map-organizations-bsffbfs4m"},"datePublished":"2026-07-14T07:00:31.556Z","dateModified":"2026-07-14T07:00:56.482Z","description":"Datadog researchers have uncovered coordinated, multi-month campaigns abusing GitHub's API and reactivated 'ghost' accounts to map organizations, their...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/27f73b7edd24039e1dd314eea049ef23?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/27f73b7edd24039e1dd314eea049ef23?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"DevOps.com","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"DevOps.com","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/db8f2265cff0416c878c6e7e92bb8715","url":"https://daily.dev/sources/devops"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/github-api-abuse-ghost-accounts-part-of-malicious-efforts-to-map-organizations-bsffbfs4m","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,github,data-exfiltration","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"DevOps.com","item":"https://daily.dev/sources/devops"},{"@type":"ListItem","position":3,"name":"GitHub API Abuse, ‘Ghost’ Accounts Part of Malicious Efforts to Map Organizations"}]}
```

