HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

One‑Click VS Code Exploit Enables Theft of Full GitHub OAuth Tokens, Threatening Repo Confidentiality

A newly disclosed VS Code‑based attack allows an adversary to steal a developer’s GitHub OAuth token with a single click, providing read/write access to all repositories, including private code. The technique bypasses traditional endpoint detection and poses a significant risk to organizations that rely on GitHub for software development and third‑party integrations.

LiveThreat™ Intelligence · 📅 June 04, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

One‑Click VS Code Exploit Enables Theft of Full GitHub OAuth Tokens, Threatening Repo Confidentiality

What Happened — Researchers disclosed a single‑click attack delivered through Microsoft Visual Studio Code that automatically captures a victim’s GitHub OAuth token. The token grants read/write access to all repositories, including private ones, allowing attackers to exfiltrate source code, inject malicious changes, or harvest intellectual property.

Why It Matters for TPRM

  • Compromise of a developer’s token can expose proprietary code and supply‑chain assets across multiple third‑party integrations.
  • Attack leverages a trusted development environment, making detection difficult for traditional endpoint controls.
  • Organizations that rely on GitHub for CI/CD, open‑source contributions, or internal tooling face elevated risk of data leakage and sabotage.

Who Is Affected — Technology & SaaS firms, software development teams, cloud‑native service providers, and any third‑party that integrates with GitHub (e.g., CI/CD platforms, DevSecOps tools).

Recommended Actions

  • Enforce MFA and token‑scoping policies for all GitHub OAuth applications.
  • Deploy URL‑filtering and anti‑phishing controls to block malicious links targeting VS Code.
  • Conduct token rotation and revoke any tokens issued before the advisory.
  • Review VS Code extension policies and restrict installation of unverified extensions.

Technical Notes — The attack exploits the github.dev web‑based editor invoked from VS Code. By tricking a user into clicking a crafted link, the attacker triggers VS Code to open a malicious workspace that silently captures the OAuth token via a hidden request. No CVE has been assigned; the vector is a phishing‑style UI redirection. Data at risk includes source code, proprietary algorithms, and any secrets stored in repositories. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.