Visual Studio Code GitHub Token Theft Zero-Day | MSSP Advisory

HighCredible Report
DateJune 3, 2026
📋Executive Summary
A publicly disclosed zero-day in Visual Studio Code allows an attacker to steal GitHub OAuth tokens by tricking a user into clicking a single link. The exploit abuses VS Code's sandboxed webview message-passing system to silently install a malicious extension, extract the GitHub token passed to github.dev, and enumerate every private repository the victim can access. No CVE has been assigned and no patch exists yet, but researcher Ammar Askar published working proof-of-concept code alongside the disclosure.
⚠️Why It Matters for MSSPs
Any developer or engineer on your team or in your client accounts who uses VS Code and touches GitHub repositories is one click away from handing an attacker full read access to every private repo they have permissions on, including infrastructure-as-code, deployment scripts, and credential files. If your team stores client environment configs, Terraform templates, or API keys in GitHub repos, this is a direct threat to your own stack. Clients running software development environments or DevOps pipelines are equally exposed, and if one of them gets hit after you said nothing, that is your liability to carry.
Recommended Action
Send a client advisory today naming this VS Code zero-day by source, direct every developer and engineer in your accounts and on your own team to open their browser, go to github.dev settings, clear all cookies and local site data for that domain, and do not click any external links that redirect to github.dev until Microsoft ships a patch.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.