One Click in github.dev Could Reach Every Repository the Developer Could.

A malicious notebook could turn github.dev into a GitHub OAuth-token theft path with read and write access across the developer's repositories.

A malicious notebook could turn github.dev into a GitHub OAuth-token theft path with read and write access across the developer's repositories.

A compromised Nx Console update reached a GitHub employee device, stole credentials, and exposed roughly 3,800 internal repositories.