Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

One‑Click VS Code Exploit Enables Theft of Full GitHub OAuth Tokens, Threatening Repo Confidentiality

A newly disclosed VS Code‑based attack allows an adversary to steal a developer’s GitHub OAuth token with a single click, providing read/write access to all repositories, including private code. The technique bypasses traditional endpoint detection and poses a significant risk to organizations that rely on GitHub for software development and third‑party integrations.

LiveThreat™ Intelligence · 📅 June 04, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

One‑Click VS Code Exploit Enables Theft of Full GitHub OAuth Tokens, Threatening Repo Confidentiality

What Happened — Researchers disclosed a single‑click attack delivered through Microsoft Visual Studio Code that automatically captures a victim’s GitHub OAuth token. The token grants read/write access to all repositories, including private ones, allowing attackers to exfiltrate source code, inject malicious changes, or harvest intellectual property.

Why It Matters for TPRM —

  • Compromise of a developer’s token can expose proprietary code and supply‑chain assets across multiple third‑party integrations.
  • Attack leverages a trusted development environment, making detection difficult for traditional endpoint controls.
  • Organizations that rely on GitHub for CI/CD, open‑source contributions, or internal tooling face elevated risk of data leakage and sabotage.

Who Is Affected — Technology & SaaS firms, software development teams, cloud‑native service providers, and any third‑party that integrates with GitHub (e.g., CI/CD platforms, DevSecOps tools).

Recommended Actions —

  • Enforce MFA and token‑scoping policies for all GitHub OAuth applications.
  • Deploy URL‑filtering and anti‑phishing controls to block malicious links targeting VS Code.
  • Conduct token rotation and revoke any tokens issued before the advisory.
  • Review VS Code extension policies and restrict installation of unverified extensions.

Technical Notes — The attack exploits the github.dev web‑based editor invoked from VS Code. By tricking a user into clicking a crafted link, the attacker triggers VS Code to open a malicious workspace that silently captures the OAuth token via a hidden request. No CVE has been assigned; the vector is a phishing‑style UI redirection. Data at risk includes source code, proprietary algorithms, and any secrets stored in repositories. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →