Twitch extension with 30K installs exposes users’ OAuth tokens

Summary

A Twitch browser extension with over 30,000 installations has been found to be exfiltrating users' Twitch OAuth session tokens to a commercial bot service. This data could potentially be used to hijack user accounts.

IFF Assessment

FOE

The exposure of user OAuth tokens by a browser extension poses a significant risk to user account security, enabling potential hijacking and unauthorized access.

Defender Context

This incident highlights the ongoing risks associated with third-party browser extensions and the importance of scrutinizing their permissions and data handling practices. Defenders should educate users about the potential dangers of installing unverified extensions and advise on best practices for managing OAuth tokens and account security.

Read Full Story →