1-Click Account Takeover — Immutable Passport

XSS on biome-storybook.immutable.com → OAuth code theft via auth.immutable.com/im-logged-in open redirect → token exchange → full ATO

Chain: postMessage XSS → cookie theft → OAuth authorization code theft → token exchange → ATO
Interaction: 1-click (button to start the OAuth redirect)
Impact: Attacker obtains access_token (scope: transact) + refresh_token (persistent access) + id_token (PII: email, wallet addresses)

Attack Controls

Exfiltrated Data

Storybook iframe (hidden in real attack)