Twitch extension with 30K installs exposes users’ OAuth tokens
Summary
A Twitch browser extension with over 30,000 installations has been found to be exfiltrating users' Twitch OAuth session tokens to a commercial bot service. This data could potentially be used to hijack user accounts.
IFF Assessment
FOE
The exposure of user OAuth tokens by a browser extension poses a significant risk to user account security, enabling potential hijacking and unauthorized access.
Defender Context
This incident highlights the ongoing risks associated with third-party browser extensions and the importance of scrutinizing their permissions and data handling practices. Defenders should educate users about the potential dangers of installing unverified extensions and advise on best practices for managing OAuth tokens and account security.