Skip to content
Threat Feed
low advisory

GitHub OAuth Application Authorization Persistence

Attackers can achieve persistent unauthorized access to GitHub repositories by abusing OAuth application grants, which remain valid even after user password resets.

This threat involves the abuse of GitHub OAuth application authorization (oauth_authorization.create) to establish persistent access to an environment. Unlike GitHub App installations, user-authorized OAuth applications provide tokens that grant the application access to the user's data, including private repositories. A critical risk is that these OAuth grants persist even if the user changes their GitHub account password, as the authorization is tied to the grant rather than just the user's credentials. Attackers leverage this mechanism to maintain access to repositories, clone code, or download ZIP archives long after initial compromise. Detection of this activity requires monitoring GitHub audit logs for OAuth grant events and pivoting to subsequent repository access logs.

Impact

Successful exploitation allows attackers to clone private repositories or download source code, potentially leading to the exfiltration of sensitive intellectual property, secrets, or API keys. Because these grants persist beyond password resets, this technique provides a durable backdoor into development environments, affecting organizations relying on GitHub for code hosting and CI/CD pipelines.

Recommendation

Detection and response teams should implement monitoring for unauthorized OAuth application grants and maintain strict governance over third-party integrations.

  • Implement monitoring for the oauth_authorization.create action within GitHub audit logs to alert on unexpected or suspicious application grants.
  • Establish an allowlist of approved internal and vendor OAuth applications and investigate any grant that does not match this list.
  • For suspected unauthorized access, immediately revoke the OAuth grant, invalidate existing tokens, reset the compromised user's password, and invalidate active sessions.
  • Review organization-wide third-party application restrictions to limit the scope and risk of OAuth grants.

Immediate actions

Implement audit log monitoring for oauth_authorization.create events.

Detection Engineering 72h

Threat Hunt

Review recent oauth_authorization.create events for applications not on the approved allowlist.

T1078.004 high high confidence hunt now

Data: GitHub audit logs