GitHub is becoming a reconnaissance layer, not just a code host. Weeks of ordinary-looking public API calls can assemble a detailed map of organizations, members, repos, and related activity without tripping alerts that only watch for big bursts or obvious login abuse.
Datadog says the campaign has run for months and mixes automated scanners, leaked credentials, and burner accounts. The calls are individually unremarkable, but over time they reveal which orgs exist, who belongs to them, and which repositories are worth cloning or searching for secrets.
The risk is the low-and-slow phase. By the time repository cloning starts, the attacker already has a target map that spans tenants and blends into normal developer traffic.