Threat reportVulnerabilityTL-2026-0667

VSCode Webview 1-Click GitHub OAuth Token Theft — postMessage Keydown-Forwarding Boundary Bypass on github.dev (Full Disclosure, Public PoC)

criticalACTIVE

VSCode Webview 1-Click GitHub OAuth Token Theft (TL-2026-0667), also tracked as 1-Click GitHub Token Stealing via VSCode Bug, is a critical-severity software vulnerability, first published 2026-06-02. It has no confirmed attribution, affects GitHub github.dev (browser-hosted VSCode), maps to 13 MITRE ATT&CK techniques (T1059, T1071, T1176), and is covered by 9 detection rules and 16 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
13MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0667

Threat ID
TL-2026-0667
Also known as
1-Click GitHub Token Stealing via VSCode Bug, github.dev OAuth Token Theft
Severity
CRITICAL
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, software development, open source, financial services, government, healthcare
Target regions
Global
Detection rules
9
Indicators of compromise
16

Malware and tooling in VSCode Webview 1-Click GitHub OAuth Token Theft

Malware and tooling: AmmarTest.hello-ammar-github

How VSCode Webview 1-Click GitHub OAuth Token Theft works

A critical, unpatched VSCode webview vulnerability lets an attacker steal a victim's unscoped GitHub OAuth token (read/write to ALL private repositories) with a single malicious github.dev link click. VSCode's did-keydown handler forwards untrusted webview keyboard events to the main editor window via Window.postMessage(), allowing attacker JavaScript to synthesize keystrokes, silently sideload a local extension with skipPublisherTrust, read the preloaded OAuth token, and exfiltrate it plus the victim's private-repo list. Disclosed June 2, 2026 by researcher Ammar Askar with a full public proof-of-concept; the desktop VSCode variant escalates to full RCE via Node.js child_process.

This is a security-boundary bypass in the Visual Studio Code webview architecture, weaponized against GitHub's browser-hosted editor github.dev to achieve one-click theft of a fully-scoped GitHub OAuth token.

ROOT CAUSE — UNTRUSTED WEBVIEW CAN FORGE TRUSTED KEYSTROKES: VSCode renders webview content inside iframes whose origin (vscode-webview://) is deliberately isolated from the main editor origin (vscode-file://). For keyboard shortcuts to work while a webview is focused, VSCode registers a keydown listener inside the webview that forwards every keypress to the host window via a 'did-keydown' postMessage. The host then re-dispatches these as if the user pressed them. There is no check that the keydown originated from genuine user input, so JavaScript executing in an untrusted webview can synthesize arbitrary KeyboardEvent objects and drive the trusted main window — collapsing the boundary between 'Untrusted User Content' and 'Dangerous APIs.'

UNSCOPED OAUTH TOKEN ON github.dev: When a user navigates from github.com to github.dev for any repository, github.com auto-POSTs an OAuth token into the github.dev session. Critically, this token is NOT scoped to the repo the user opened — it grants full read/write access to every repository the user can reach. github.dev implements no CSRF protection, so any link anywhere on the internet can silently redirect a victim into a github.dev workspace under attacker control.

EXPLOIT CHAIN (executes in well under a minute, zero interaction beyond the initial click): 1. INITIAL ACCESS / EXECUTION — The victim clicks a link to an attacker-controlled github.dev repo opening a malicious Jupyter notebook (README.ipynb). A notebook cell contains <img src="data:foobar" onerror="..."> whose onerror handler runs attacker JavaScript inside the webview. 2. NOTIFICATION ACCEPT — The script dispatches a synthetic Ctrl+Shift+A keydown ('Notifications: Accept Notification Primary Action'), accepting the 'install recommended extensions' prompt produced by an attacker-supplied .vscode/extensions.json. 3. PUBLISHER-TRUST BYPASS — Rather than a Marketplace extension (which since VSCode 1.89 requires publisher trust), the attacker ships a LOCAL workspace extension placed directly in .vscode/extensions/. github.dev workspaces are always trusted, so the local extension loads. Its package.json contributes a keybinding (Ctrl+F1 -> runCommands -> workbench.extensions.installExtension) that installs the real payload extension with context skipPublisherTrust:true, fully bypassing the publisher-trust dialog. 4. KEYBINDING TRIGGER — The script dispatches a synthetic Ctrl+F1 keydown to fire that keybinding. 5. TOKEN THEFT & EXFIL — The installed extension runs with full VSCode API access, reads the preloaded GitHub OAuth token, enumerates every private repository via https://api.github.com/user/repos, and exfiltrates the token plus the private-repo list to the attacker.

DESKTOP IMPACT — RCE: The same webview keydown-forwarding flaw exists in desktop VSCode. Exploitation is harder (the victim must clone/open the attacker's repository and open the notebook), but a loaded extension has unrestricted Node.js APIs including child_process, escalating to full remote code execution on the developer workstation.

DEFENSE-IN-DEPTH THAT DID NOT STOP IT: VSCode applies a strict CSP (script-src 'none') on extension Markdown/preview pages and uses DOMPurify to sanitize rendered HTML, which blocked simpler injection vectors — but neither prevents an untrusted webview from synthesizing keyboard events to drive the host.

DISCLOSURE: Researcher Ammar Askar published a full public disclosure on June 2, 2026, including working PoC repositories, after citing prior negative experiences with Microsoft's MSRC (silent fixes without credit, incorrect severity assessments). GitHub Security was notified roughly one hour before public posting; the corresponding microsoft/vscode issue #319593 was filed the same day. No vendor patch existed from Microsoft or GitHub at the time of disclosure. No CVE had been assigned by the source at disclosure.

MITRE ATT&CK techniques used in TL-2026-0667

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution

Command and Control

T1071 Application Layer Protocol

Persistence

T1176 Software Extensions

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

Collection

T1213 Data from Information Repositories

Credential Access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

lateral-movement

T1550 Use Alternate Authentication Material

defense-impairment

T1553 Subvert Trust Controls

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in VSCode Webview 1-Click GitHub OAuth Token Theft

  • GitHub — github.dev (browser-hosted VSCode)
    Vulnerable versions: live service as of 2026-06-02
    Fixed in: none at disclosure
  • Microsoft — Visual Studio Code (desktop)
    Vulnerable versions: 1.89+ (publisher-trust era; webview did-keydown forwarding present)
    Fixed in: none at disclosure
  • Microsoft — VSCode webview implementation (did-keydown postMessage forwarding)
    Vulnerable versions: all builds with did-keydown host forwarding
    Fixed in: none at disclosure

Remediation for VSCode Webview 1-Click GitHub OAuth Token Theft

Patches

  • No vendor patch available from Microsoft or GitHub at time of disclosure (June 2, 2026). Track microsoft/vscode issue #319593 for the fix.

Immediate actions

  • Clear github.dev site data in the browser (Chrome: URL-bar site-info icon -> Cookies and site data -> Delete domain data) to purge the cached OAuth token and re-enable the first-visit consent dialog.
  • Avoid clicking unknown or untrusted github.dev links until Microsoft/GitHub ship a patch.
  • Audit installed github.dev extensions and uninstall anything unrecognized or recently auto-installed.
  • Consider blocking github.dev at the web proxy/DNS layer organization-wide until patched.

Workarounds

  • Clearing github.dev local/site storage restores the initial sign-in consent dialog, providing a brief intervention point.
  • Disable or block github.dev usage across the organization until a fix ships.
  • For desktop VSCode, do not clone/open untrusted repositories or notebooks; keep Workspace Trust enabled.

Longer-term hardening

  • Treat any exposed token as fully compromised: revoke GitHub OAuth authorizations/sessions and rotate affected credentials and PATs.
  • Monitor GitHub audit logs for anomalous https://api.github.com/user/repos enumeration and unexpected pushes/clones across private repos.
  • Enforce least-privilege, repo-scoped tokens; press GitHub to scope the github.dev token to the opened repository only.
  • Deploy enterprise browser policies and EDR to detect malicious VSCode/IDE extension installation and child_process abuse on developer endpoints.

Weaknesses (CWE) in VSCode Webview 1-Click GitHub OAuth Token Theft

CWE-940, CWE-346, CWE-501, CWE-829, CWE-272

Timeline of VSCode Webview 1-Click GitHub OAuth Token Theft

  • Ammar Askar identifies that VSCode's did-keydown handler forwards untrusted webview keyboard events to the main window and that github.dev issues an unscoped OAuth token, enabling a 1-click token-theft chain (research predates public disclosure).
  • No patch available from Microsoft or GitHub at time of disclosure; github.dev remains exploitable and no CVE assigned by the source.
  • microsoft/vscode issue #319593 filed regarding the webview keydown-forwarding security boundary.
  • Public proof-of-concept repositories released: github-dev-token-steal-poc (malicious README.ipynb notebook) and vscode-github-token-grab-extension (token-grabbing extension).
  • Full public disclosure published on Ammar Askar's blog with complete technical write-up and step-by-step exploit chain.
  • GitHub Security notified approximately one hour before public disclosure; no coordinated disclosure with Microsoft MSRC due to prior negative experiences.
  • Cyber Security News publishes coverage detailing the 1-click GitHub OAuth token theft and desktop RCE escalation.

Sources cited for VSCode Webview 1-Click GitHub OAuth Token Theft

Detection coverage for TL-2026-0667

As of 2026-06-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0667 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats