One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
EXPIRED
58.5
2026-06-04T07:00
Score-Aufschlüsselung
100
novelty
25
reach
45
concrete_impact
65
emotional_hook
70
source_quality
55
platform_fit
Zusammenfassung
Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token. "Just by clicking a link, it's possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones," security researcher Ammar Askar said. GitHub supports a feature called GitHub.dev that runs as
Skripte (0)
626fb284…
Noch kein Skript generiert.
Score 58.5 — unter Schwellwert (65)