Interestana
Home/News/Twitch Extension Leaks User OAuth Tokens
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Twitch Extension Leaks User OAuth Tokens

A critical security vulnerability has been identified in the Twitch Enhanced Viewer | JeetBot browser extension, which has garnered over 30,000 installations across official Chrome and Firefox web stores. This extension, designed to enhance the Twitch viewing experience, has been discovered to be exfiltrating users' Twitch OAuth session tokens to a commercial bot service. The OAuth tokens are sensitive credentials that grant third-party applications access to a user's account without requiring their password. By obtaining these tokens, malicious actors could potentially gain unauthorized access to user accounts, enabling them to perform actions such as posting unauthorized messages, changing account settings, or even initiating fraudulent transactions. The vulnerability was brought to light by security researcher Zach Edwards, who detailed the findings in a series of posts on X (formerly Twitter). Edwards' investigation revealed that the extension was sending these tokens to a server operated by a bot service, indicating a potential for widespread account compromise among its user base. The implications of such a data leak are significant, as compromised OAuth tokens can be used to impersonate users, spread misinformation, or engage in other malicious activities under the guise of legitimate account holders. Twitch Enhanced Viewer | JeetBot is available on both the Chrome Web Store and the Firefox Add-ons website, making it accessible to a broad range of users. The exact nature of the bot service receiving the tokens has not been fully disclosed, but its commercial operation suggests a potential for monetization of the stolen data. Users who have installed the Twitch Enhanced Viewer | JeetBot extension are strongly advised to revoke its access from their Twitch account immediately and remove the extension from their browser. This incident underscores the persistent risks associated with third-party browser extensions, even those hosted on official marketplaces, and highlights the importance of vigilant security practices for online users. The discovery serves as a stark reminder that extensions, while offering convenience, can also introduce significant security vulnerabilities if not developed and maintained with robust security protocols. The potential for attackers to leverage these leaked tokens for further exploitation remains a pressing concern for the Twitch community and its millions of users worldwide. The security researcher's findings have prompted discussions about the vetting processes for browser extensions and the responsibility of platform providers in safeguarding user data from such breaches. The lack of immediate action by the extension's developers to address the vulnerability further exacerbates the risk to users, leaving them exposed to potential account hijacking and other security threats.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next