A VS Code exploit for github.dev can steal GitHub OAuth tokens after one malicious link, exposing private repositories while teams await a patch.
GitHub says hackers stole about 3,800 internal repos after a poisoned VS Code extension hit an employee device ...