The security researcher, Ammar Askar, released the new proof-of-concept exploit on his personal blog, alongside the public tracker for issues in VS Code, giving a GitHub security contact roughly one hour’s notice beforehand.
First seen on therecord.media
Jump to article: therecord.media/researcher-publishes-github-token-stealing-exploit-microsoft
![]()

