Researchers managed to steal GitHub OAuth tokens by abusing a command injection vulnerability.