Another comment mentions GitHub themselves detecting the breach - in this case it's unlikely to be done via a compromised developer's laptop as the access would otherwise look normal and wouldn't trigger GH's security alerts.
Anyway many legit reasons. Should it set off an alarm? Probably. Can you say before you do it? For sure!