{"success":true,"data":{"id":"workspace-oauth-app-install-lure","label":"Workspace OAuth app install lure — email asks you to authorize a Slack / Teams / Jira / Notion / Asana app with broad scopes like channels:history or drive.readonly (2026 shadow-IT / SaaS compromise vector)","description":"Email lures the recipient into authorizing a malicious OAuth application on a collaboration platform (Slack, Microsoft Teams, Atlassian / Jira / Confluence / Trello, Notion, Asana, Linear, Zoom, Google Workspace, Monday, GitHub, GitLab, Bitbucket). One user approval on the consent screen grants the attacker persistent API-level access with the requested scopes — channels:history + chat:write (Slack), Chat.Read + Files.Read.All (Teams), jira:read + jira:write (Atlassian), drive.readonly (Google Workspace). No password, no MFA, no further user interaction needed; the attacker can read every message, download every file, and persist indefinitely until the token is manually revoked by an admin. Fires when body contains app-install flow language for a specific named platform AND OAuth / consent / scope / permissions language. Excludes known workspace-platform vendors (Slack, Microsoft, Atlassian, Notion, Asana, Linear, Zoom, Google, Monday, GitHub, GitLab, Bitbucket, Trello, Salesforce, Smartsheet), reply threads, and newsletters. Auto-classified as danger via the `-lure` suffix.","tier":"danger","category":"phishing","isThin":false}}