Skip to content
Discussion options

You must be logged in to vote

If an app got added to your GitHub account without you approving it, you should treat it as a possible account hack. First, remove the app from Settings → Applications → Authorized OAuth Apps, then change your password and turn on two-factor authentication. Also check your access tokens, SSH keys, and your security log
for anything suspicious. To let GitHub know, you can email security@github.com
or report it through their HackerOne page When you report, include the app’s name, when it was added, and what you found in your security log so GitHub can properly investigate.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@stwom-user
Comment options

@stwom-user
Comment options

Answer selected by stwom-user
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
other General topics and discussions that don't fit into other categories, but are related to GitHub Question Ask and answer questions about GitHub features and usage
2 participants