
GitHub has a unique security feature - it scans the code for exposed Amazon Web Services (AWS) keys (among other things) and if it finds them, it reports them to AWS which can act to prevent misuse - all within minutes.
However, it doesn’t work with 100% accuracy, and sometimes keys stay exposed for a bit longer. Some hackers managed to take advantage of that window of opportunity, grabbing the keys and creating Amazon Elastic Compute Cloud (EC2) instances.