I can understand how AWS can react quickly using the secrets scanning service but how do malicious actors do it without having access to that service?
(not sure why really)
It's probably just polling and luck to be honest.
https://docs.github.com/en/code-security/secret-scanning/abo...
Maybe they have a bot watching some "latest thing on github" API, that scans everything coming in for credentials.