31,000 Twitch users hit by malicious browser extension — OAuth tokens leaked via Russian proxy network
The extension has since been updated to remove the OAuth exfil.
A malicious browser extension for Twitch, "Twitch Enhanced Viewer | JeeBot," has compromised the OAuth tokens of approximately 31,000 users. The extension, found on both Chrome and Firefox, was designed to harvest these tokens via Russian proxy servers. It was advertised as a tool for streamers and viewers, offering features like clearer streaming, 2K viewing, ad blocking, and even an AI bot for easier interaction.
However, the developers inadvertently placed users' OAuth tokens in the proxy server's request logs. After being exposed, the developer released an update to fix the issue, but it appears that the tokens were being forwarded to the proxies, even if only for 10 Russian streamer channels. Security researchers advise users to revoke their exposed Twitch tokens for safety measures.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.