logo

VS Code zero-day lets hackers steal GitHub tokens in one click

ID: c577fe83-f941-56a7-b782-88d0af1cfc17

STIX ID: report--c577fe83-f941-56a7-b782-88d0af1cfc17

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Sergiu Gatlan

...
...

A security researcher published a proof-of-concept for a Visual Studio Code zero-day that allows attackers to trick users into installing malicious extensions which steal GitHub OAuth tokens via github.dev's webview messaging; the stolen tokens can be used to access and enumerate private repositories. The flaw was publicly disclosed without an available patch, and mitigations include clearing github.dev cookies and local site data to force a sign-in warning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.