logo

OAuth marketplace apps keep access after publishers vanish

ID: 893caae6-0a01-5cd2-bbaa-ba45f4cd7e39

STIX ID: report--893caae6-0a01-5cd2-bbaa-ba45f4cd7e39

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Mirko Zorz

...
...

### Executive summary An Offroad/OAuth audit of 2,890 public marketplace OAuth apps (1,595 Google Workspace, 1,295 GitHub) found 918 apps (32%) showing at least one exposure signal—overbroad scopes relative to function, AI apps with broad write access, dead or buyable publisher domains, and domain threat-intel flags—covering a lower-bound combined install footprint of roughly 1.85 billion. The audit highlights large-scale supply-chain and identity risks from long-lived OAuth grants, limited continuous marketplace re-validation, and recommends inventorying grants, tighter scope justification, monitoring high-privilege actions, separation of AI apps, and scheduled rotation or revocation of high-risk authorizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.