Interestana
Home/News/Twitch Extension Leaks OAuth Tokens for 31,000 Users
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Twitch Extension Leaks OAuth Tokens for 31,000 Users

Twitch Extension Leaks OAuth Tokens for 31,000 Users

A malicious browser extension designed for Twitch, identified as "Twitch Enhanced Viewer | JeetBot," has led to the exposure of OAuth tokens belonging to approximately 31,000 users. These tokens were transmitted to proxy servers operated by a Russian commercial bot service, posing a significant security risk to affected accounts. The developer is listed as HISHIMIRO/jeetbot.cc, and the extension was available on both the Google Chrome Web Store and the Mozilla Firefox Add-Ons store. OAuth tokens are critical security credentials that grant applications permission to access user accounts on their behalf without requiring users to share their passwords directly. The compromise of these tokens could allow unauthorized actors to gain access to users' Twitch accounts, potentially enabling them to post unauthorized content, send malicious messages, or engage in other harmful activities. The specific mechanism by which the tokens were exfiltrated and the full extent of the data accessed by the bot service remain under investigation. This incident highlights the ongoing threat posed by malicious browser extensions, which can often masquerade as legitimate tools while secretly harvesting sensitive user information. Users are advised to review their installed browser extensions and revoke access for any suspicious or unverified applications. The Chrome Web Store and Mozilla Add-Ons store have policies against malicious software, but sophisticated threats can sometimes evade detection. The availability of such extensions on official marketplaces underscores the need for continuous vigilance from both platform providers and end-users. The Russian commercial bot service involved in operating the proxy servers has not yet been identified by name, but its commercial nature suggests a potential for financial motivation behind the data exfiltration. The implications of this breach extend beyond simple account hijacking, as compromised OAuth tokens can sometimes be chained with other vulnerabilities to facilitate more widespread attacks or identity theft. The number of affected users, nearly 31,000, indicates a substantial scale for this particular incident, making it a notable event in the ongoing landscape of online security threats. The investigation into the full impact and the actors behind the malicious extension is likely to continue, with potential for further details to emerge regarding the specific data compromised and the methods employed. The incident serves as a stark reminder of the importance of scrutinizing browser extensions before installation and regularly auditing permissions granted to third-party applications. The compromised tokens could potentially be used to access linked accounts or services if users have reused credentials or granted similar permissions elsewhere. The security community is closely monitoring this situation for any updates on mitigation strategies and the identification of the perpetrators. The reliance on browser extensions for enhanced functionality on platforms like Twitch, while convenient, introduces a vector for potential security vulnerabilities that requires careful management.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next