Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
- ID
- 24143
- Status
- summarized
- Published
- 14 Sep 2026, 3:24 PM
- Fetched
- 14 Sep 2026, 5:58 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.5
- Created
- 14 Sep 2026, 6:02 PM
- Tags
- Audience
- developers
What happened
A malicious Twitch browser extension called 'Twitch Enhanced Viewer | JeetBot' has leaked OAuth tokens from ~31,000 users (30,000 Chrome, 604 Firefox) to proxy servers run by a Russian commercial bot service. The extension forwards the token as an &auth= query parameter on every channel a user watches, except for a hardcoded allowlist of 10 Russian streamer channels. Both extensions remain available for download as of the article date.
Why it matters
This is a niche consumer-browser-extension incident with no direct impact on AI/ML, developer tooling, SaaS, or Malaysian tech infrastructure. The only transferable lesson is that browser extensions with broad host permissions can silently exfiltrate OAuth tokens via URL query parameters logged in cleartext — relevant only if your team ships or reviews browser extensions.
Discussion angle
If anyone in the group builds or audits browser extensions, this is a concrete example of why OAuth tokens should never be passed as URL query parameters and why broad host permissions warrant scrutiny — otherwise skip this item.