ScamLens
Technical bleeping computer · 6/3/2026

VS Code zero-day lets hackers steal GitHub tokens in one click

This is a standalone intelligence detail page built for indexing and citation, with the summary, linked domains, and next verification paths in one place.

Quick Answer

A VS Code zero-day vulnerability allows attackers to steal GitHub authentication tokens via malicious links. Security researcher released exploit code enabling credential theft through single-click attacks on developers.

1 linked domains surfaced
Tagged as Phishing / Identity Theft
Intelligence grade actionable

bleeping computer

Source

HIGH

Importance

1

Linked Domains

0

Linked Addresses

AI Summary

A VS Code zero-day vulnerability allows attackers to steal GitHub authentication tokens via malicious links. Security researcher released exploit code enabling credential theft through single-click attacks on developers.

Scam Labels

Phishing Identity Theft

Linked Domains