How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign

This Wiz blog post presents a practical investigation playbook drawn from the Wiz Customer Incident Response Team's response to a coordinated campaign targeting GitHub Personal Access Tokens (PATs) across multiple organizations between May and June 2026. The attack followed three phases: reconnaissance via the GitHub API from an AWS IP address using a Chrome user agent, low-volume validation cloning from HostPapa infrastructure to confirm token validity, and finally a mass parallelized repository cloning operation using 102 AWS IP addresses in the ca-central-1 region with a git/2.43.0 user agent. The investigation methodology includes reviewing GitHub audit logs and personal security logs to establish baselines and identify anomalies, pivoting on indicators of compromise, and engaging GitHub Support for additional logs. The initial access vector—how the attacker obtained valid PATs across multiple unrelated organizations—remained unidentified in the investigation. The post recommends reviewing audit logs for anomalous clone activity, revoking compromised PATs, implementing GitHub Enterprise Log Streaming for visibility into API-based reconnaissance, auditing for hardcoded secrets in accessed repositories, and isolating affected endpoints. 

https://www.wiz.io/blog/investigating-github-pat-compromise

Comments

Popular posts from this blog

OWASP ASVS 5.0 Released - Key Updates and What You Need to Know

Critical OpenSSH Flaws Enable MITM and DoS Attacks

MITRE ATT&CK v19 Redefines How Defenders Model Modern Threats