SECURITYTHE HACKER NEWS
One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
Cybersecurity researchers disclosed a one-click attack via Microsoft Visual Studio Code that can steal GitHub OAuth tokens, allowing attackers to read and write to user repositories, including private ones. The attack exploits GitHub's GitHub.dev feature, enabling token theft through a malicious link click.
Mentioned
Related Signal
Adjacent reporting
- VS Code zero-day lets hackers steal GitHub tokens in one click
- 1-Click GitHub Token Stealing via a VSCode Bug
- Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
- Vercel Employee's AI Tool Access Led to Data Breach
- 'TrustFall' Exposes Claude Code Execution Risk
- Grafana says stolen GitHub token let hackers steal codebase