A post published on DEV.to on September 2, 2026, openly advertised marketplaces selling aged GitHub accounts, drawing immediate scrutiny from developers concerned about platform integrity and security implications.

What Are Aged Accounts?

Aged GitHub accounts are profiles with established histories—older account creation dates, accumulated contribution graphs, and verified activity patterns. These characteristics make them appear trustworthy to automated systems that flag new or low-activity accounts for review or restrictions. The DEV.to article, titled "14 Sites to Purchase Aged GitHub Accounts," included contact information for vendors via Telegram (username @progmbofficial), WhatsApp at +1 (920) 212-9737, and email (progmb.contact@gmail.com). The full source content was corrupted in transmission, preventing detailed analysis of the specific marketplaces listed.

Why Developers Should Care

GitHub explicitly prohibits account trading under its Terms of Service. Section 4 states that users must "not share your GitHub account with anyone else" or "transfer your account to another person or entity." Purchasing aged accounts bypasses these restrictions and creates several risks: First, bought accounts may contain trojans, backdoors, or malicious automation scripts embedded by previous owners. Second, organizations relying on contribution history for due diligence can be deceived into trusting compromised developers. Third, the secondary market incentivizes credential theft and account takeover campaigns.

Industry Response

Security researchers have documented how aged accounts fuel spam operations, cryptocurrency scams on open-source repositories, and supply chain attacks where malicious code is merged under seemingly legitimate commit histories. The GitHub Trust & Safety team maintains active detection systems for accounts displaying suspicious acquisition patterns, though enforcement remains reactive rather than preventive.

Key Takeaways

  • Aged account marketplaces violate GitHub's Terms of Service and enable fraud
  • Purchased accounts may contain embedded malware from previous owners
  • Organizations cannot rely on account age as a trust signal when buying is an option
  • Report suspected account trading to GitHub via their Trust & Safety portal

The Bottom Line

This DEV.to post is gone, but the market it promoted won't be. If you're hiring developers or reviewing pull requests, treat account history as noise—not signal. Build your review process around code quality, not graveyard-aged profiles that anyone can buy for fifty bucks on a Telegram channel.