Attackers are using networks of dormant GitHub accounts to map corporate development teams and steal source code.