Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Cyber > VS Code Vulnerability Allows One-Click GitHub Token Theft

VS Code Vulnerability Allows One-Click GitHub Token Theft

Researcher exposes VS Code flaw enabling GitHub token theft.

Ammar Askar publicly disclosed a VS Code vulnerability that lets attackers steal a user’s GitHub token through a malicious Jupyter notebook opened on github.dev. Hidden code can simulate keystrokes to install a rogue extension that sends the victim’s token to the attacker, granting full access to all repositories. Microsoft patched the web version on June 3, though the desktop version remains harder to exploit and still unpatched. The disclosure follows other recent zero‑days released without vendor notification, prompting tense exchanges between researchers and Microsoft.

Read more:

https://www.securityweek.com/vs-code-vulnerability-allows-one-click-github-token-theft/