A VS Code vulnerability in GitHub.dev lets attackers steal full GitHub OAuth tokens via a single malicious link, exposing all private repositories.
The codes are fixed, so you can enter the same combinations on any playthrough instead of searching for the clues again. Some locks are optional, but others lead to collectibles, story routes, or ...