# VSCode Webview 1-Click GitHub OAuth Token Theft — postMessage Keydown-Forwarding Boundary Bypass on github.dev (Full Disclosure, Public PoC)

> A critical, unpatched VSCode webview vulnerability lets an attacker steal a victim's unscoped GitHub OAuth token (read/write to ALL private repositories) with a single malicious github.dev link click. VSCode's did-keydown handler forwards untrusted webview keyboard events to the main editor window via Window.postMessage(), allowing attacker JavaScript to synthesize keystrokes, silently sideload a local extension with skipPublisherTrust, read the preloaded OAuth token, and exfiltrate it plus the victim's private-repo list. Disclosed June 2, 2026 by researcher Ammar Askar with a full public proof-of-concept; the desktop VSCode variant escalates to full RCE via Node.js child_process.

- **Published:** 2026-06-02T00:00:00Z
- **Last reviewed:** 2026-06-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0667
- **ID:** TL-2026-0667
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)

## Description

This is a security-boundary bypass in the Visual Studio Code webview architecture, weaponized against GitHub's browser-hosted editor github.dev to achieve one-click theft of a fully-scoped GitHub OAuth token.

ROOT CAUSE — UNTRUSTED WEBVIEW CAN FORGE TRUSTED KEYSTROKES: VSCode renders webview content inside iframes whose origin (vscode-webview://) is deliberately isolated from the main editor origin (vscode-file://). For keyboard shortcuts to work while a webview is focused, VSCode registers a keydown listener inside the webview that forwards every keypress to the host window via a 'did-keydown' postMessage. The host then re-dispatches these as if the user pressed them. There is no check that the keydown originated from genuine user input, so JavaScript executing in an untrusted webview can synthesize arbitrary KeyboardEvent objects and drive the trusted main window — collapsing the boundary between 'Untrusted User Content' and 'Dangerous APIs.'

UNSCOPED OAUTH TOKEN ON github.dev: When a user navigates from github.com to github.dev for any repository, github.com auto-POSTs an OAuth token into the github.dev session. Critically, this token is NOT scoped to the repo the user opened — it grants full read/write access to every repository the user can reach. github.dev implements no CSRF protection, so any link anywhere on the internet can silently redirect a victim into a github.dev workspace under attacker control.

EXPLOIT CHAIN (executes in well under a minute, zero interaction beyond the initial click):
1. INITIAL ACCESS / EXECUTION — The victim clicks a link to an attacker-controlled github.dev repo opening a malicious Jupyter notebook (README.ipynb). A notebook cell contains <img src="data:foobar" onerror="..."> whose onerror handler runs attacker JavaScript inside the webview.
2. NOTIFICATION ACCEPT — The script dispatches a synthetic Ctrl+Shift+A keydown ('Notifications: Accept Notification Primary Action'), accepting the 'install recommended extensions' prompt produced by an attacker-supplied .vscode/extensions.json.
3. PUBLISHER-TRUST BYPASS — Rather than a Marketplace extension (which since VSCode 1.89 requires publisher trust), the attacker ships a LOCAL workspace extension placed directly in .vscode/extensions/. github.dev workspaces are always trusted, so the local extension loads. Its package.json contributes a keybinding (Ctrl+F1 -> runCommands -> workbench.extensions.installExtension) that installs the real payload extension with context skipPublisherTrust:true, fully bypassing the publisher-trust dialog.
4. KEYBINDING TRIGGER — The script dispatches a synthetic Ctrl+F1 keydown to fire that keybinding.
5. TOKEN THEFT & EXFIL — The installed extension runs with full VSCode API access, reads the preloaded GitHub OAuth token, enumerates every private repository via https://api.github.com/user/repos, and exfiltrates the token plus the private-repo list to the attacker.

DESKTOP IMPACT — RCE: The same webview keydown-forwarding flaw exists in desktop VSCode. Exploitation is harder (the victim must clone/open the attacker's repository and open the notebook), but a loaded extension has unrestricted Node.js APIs including child_process, escalating to full remote code execution on the developer workstation.

DEFENSE-IN-DEPTH THAT DID NOT STOP IT: VSCode applies a strict CSP (script-src 'none') on extension Markdown/preview pages and uses DOMPurify to sanitize rendered HTML, which blocked simpler injection vectors — but neither prevents an untrusted webview from synthesizing keyboard events to drive the host.

DISCLOSURE: Researcher Ammar Askar published a full public disclosure on June 2, 2026, including working PoC repositories, after citing prior negative experiences with Microsoft's MSRC (silent fixes without credit, incorrect severity assessments). GitHub Security was notified roughly one hour before public posting; the corresponding microsoft/vscode issue #319593 was filed the same day. No vendor patch existed from Microsoft or GitHub at the time of disclosure. No CVE had been assigned by the source at disclosure.

## MITRE ATT&CK

- T1566 Phishing
- T1189 Drive-by Compromise
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1176 Software Extensions
- T1553 Subvert Trust Controls
- T1550 Use Alternate Authentication Material
- T1528 Steal Application Access Token
- T1539 Steal Web Session Cookie
- T1213 Data from Information Repositories
- T1071 Application Layer Protocol
- T1567 Exfiltration Over Web Service

## Sources

- [1-Click GitHub Token Stealing via a VSCode Bug — Ammar's Blog (primary research, PoC)](http://blog.ammaraskar.com/github-token-stealing/)
- [1-Click GitHub Token Vulnerability Lets Attackers Steal Users' OAuth Tokens](https://cybersecuritynews.com/1-click-github-token-vulnerability/)
- [PoC repository — github-dev-token-steal-poc (malicious notebook payload)](https://github.com/ammaraskar/github-dev-token-steal-poc)
- [PoC repository — vscode-github-token-grab-extension (malicious extension)](https://github.com/ammaraskar/vscode-github-token-grab-extension)
- [microsoft/vscode issue #319593 — webview keydown forwarding security boundary](https://github.com/microsoft/vscode/issues/319593)
- [Cybersecurity spotlight on bug bounty researcher Ammar Askar — The GitHub Blog](https://github.blog/security/vulnerability-research/cybersecurity-spotlight-on-bug-bounty-researcher-ammar-askar/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0667
