OAuth is an open standard for access delegation, commonly used as a way for internet users to grant websites or applications access to their information on other websites but without giving them the passwords. From Wikipedia
Investigators say the campaign relies on stolen OAuth tokens, not a Salesforce platform flaw.