Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
AI Summary
A malicious browser extension named 'Twitch Enhanced Viewer | JeetBot' has leaked OAuth tokens of nearly 31,000 users by forwarding them to proxy servers controlled by a Russian commercial bot service. The extension, available on Chrome and Firefox, sends the user's Twitch OAuth token via an &auth= query parameter during video playlist requests, exposing sensitive credentials that allow access to private messages, chat, and account settings. The token leakage occurs for all channels except a hardcoded list of 10 Russian streamers. While the developer has released a patched version (85.8.7) for Firefox, older versions continue to transmit tokens, and previously exposed tokens are not automatically revoked.
AI-extracted · verify before operational use