[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNVZZBDB4PbhkP50t8ZbuJ0NVT-ayLI4S7FXv29dClqM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"a317b093-310a-4497-a26c-4866440a644c","githubdev-extension-vulnerability-enables-oauth-token-theft","08d898fd-4335-4a1d-847e-3ab34c61e78a","GitHub.dev Extension Vulnerability Enables OAuth Token Theft","A critical vulnerability in GitHub.dev allows attackers to steal full GitHub OAuth tokens through malicious VS Code extensions that exploit webview message-passing mechanisms. The attack leverages the trusted extension ecosystem to simulate keypresses, install malicious extensions, and extract sensitive authentication tokens with complete repository access. This highlights the risks of third-party extensions in web-based development environments and the need for robust token scoping and extension validation.","**Immediate actions:**\n- Review and remove unnecessary VS Code extensions from GitHub.dev environments\n- Audit OAuth token permissions and revoke tokens with excessive privileges\n- Enable GitHub security alerts and review repository access logs for suspicious activity\n\n**Long-term improvements:**\n- Implement extension allowlisting policies for development environments\n- Configure OAuth applications with minimal required scopes and time-limited tokens\n- Establish security review processes for third-party development tools and extensions\n\n**Detection measures:**\n- Monitor OAuth token usage patterns for unusual repository access\n- Set up alerts for new extension installations in organizational accounts\n- Implement regular audits of active OAuth applications and their permissions",[12,13,14,15,16],"CIS Control 2","CIS Control 16","NIST SP 800-53 AC-6","NIST SP 800-53 SA-9","NIST Cybersecurity Framework PR.DS-6","published","2026-06-03T14:07:13.662803+00:00","2026-06-03T14:07:13.558+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002Fone-click-github-dev-attack-lets.html","one-click-github-dev-attack-lets-attackers-steal-full-github-oauth-tokens-6c431e","One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]