Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
Summary
A malicious Twitch browser extension named 'Twitch Enhanced Viewer | JeetBot' has leaked OAuth tokens from approximately 31,000 users. These tokens were exfiltrated to proxy servers controlled by a Russian commercial bot service.
IFF Assessment
FOE
The compromise of user OAuth tokens by a malicious extension represents a significant security threat, potentially leading to account takeovers and further malicious activity.
Defender Context
This incident highlights the ongoing risk posed by malicious browser extensions, even on popular platforms like Twitch. Defenders should educate users about the dangers of installing third-party extensions and monitor for signs of token exfiltration or unauthorized access to user accounts.