Close Menu
    What's Hot

    Amazon’s search bar will invent AI-generated products you can’t buy

    Beyond the Zero-Day: See Your Network Like an Attacker

    The Right Incentives for Climate Action by Paula Carvalho Pereda

    Facebook X (Twitter) Instagram
    Trending
    • Amazon’s search bar will invent AI-generated products you can’t buy
    • Beyond the Zero-Day: See Your Network Like an Attacker
    • The Right Incentives for Climate Action by Paula Carvalho Pereda
    • Trump Suggests Vance and Rubio Should Run Together in 2028 Election
    • Opinion | What Elon Musk Really Wants From the SpaceX I.P.O.
    • America Enabled the Gulf’s African Adventurism
    • Trump Confirms He Called Netanyahu ‘Crazy’ and Hopes to Meet Iran’s Supreme Leader
    • Florida Sues OpenAI and Sam Altman Over Safety Risks
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens

    adminBy adminJune 3, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 03, 2026Vulnerability / Software Development

    One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens

    Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user’s GitHub token.

    “Just by clicking a link, it’s possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones,” security researcher Ammar Askar said.

    GitHub supports a feature called GitHub.dev that runs as a lightweight web-based source code editor in the web browser’s sandbox by launching a VS Code environment. It allows users to send pull requests and make commits.

    Cybersecurity

    “This functionality is achieved by github.com POSTing over an OAuth token to github.dev that allows it to interact with GitHub on your behalf,” Askar said. “The token is not scoped to the particular repo you interacted with, meaning it has full access to every other repo that you have access to.”

    In a nutshell, the vulnerability allows attackers to install malicious VS Code extensions that steal GitHub OAuth tokens when they are passed to GitHub.dev by exploiting a message-passing mechanism between the main VS Code window and webviews. Webviews are used to render Markdown previews or edit Jupyter notebooks.

    Specifically, the exploit runs malicious JavaScript inside an untrusted webview to simulate keypresses (aka keydown events) in the main editor window, open the Command Palette by triggering “Ctrl+Shift+P,” and install an attacker-controlled extension that extracts the GitHub OAuth token sent to GitHub.dev and queries the GitHub API to enumerate all private repositories the victim can access.

    It’s worth noting the approach also leverages a VS Code feature called local workspace extensions that allows an extension to be directly installed without presenting any additional trust dialog prompt as long as it’s placed in the “.vscode/extensions” folder within that workspace, effectively bypassing the publisher trust check.

    Cybersecurity

    “This is just a small hiccup though, one of the things that extensions can do as part of their package.json is to contribute extra keybindings to VS Code,” the researcher explained. “Since we can reliably trigger keybindings, we can just add a keybind for whatever VS Code command we want, such as installing an extension while skipping the trusted publisher check.”

    The researcher also noted GitHub was notified of the vulnerability on June 2, 2026, an hour after which details of the issue were made public knowledge, citing Microsoft’s handling of VS Code-related bugs in the past. As of writing, Microsoft has acknowledged the vulnerability and noted that it’s working on a fix.

    “To clarify, this issue does not affect VS Code Desktop,” Alexandru Dima, a partner software engineering manager at Microsoft, said.

    attack Attackers dev Full GitHub Lets OAuth OneClick steal Tokens
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleOpinion | ‘Summer House’ and the Perils of Wanton Location Sharing
    Next Article TikTok launches TikTok Pro Events, an app for cultural moments like the FIFA World Cup
    admin
    • Website

    Related Posts

    Beyond the Zero-Day: See Your Network Like an Attacker

    June 3, 2026

    Iran War Live Updates: Kuwait Says One Killed and Dozens Injured in Iranian Attack on Airport

    June 3, 2026

    Microsoft debuts Surface RTX Spark Dev Box to run large AI models without cloud costs

    June 3, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Amazon’s search bar will invent AI-generated products you can’t buy

    Beyond the Zero-Day: See Your Network Like an Attacker

    The Right Incentives for Climate Action by Paula Carvalho Pereda

    Trump Suggests Vance and Rubio Should Run Together in 2028 Election

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by