CyberSecurity SEE

Malicious Twitch Extension Compromises OAuth Tokens of 31,000 Users

Malicious Twitch Extension Compromises OAuth Tokens of 31,000 Users

Malicious Twitch Browser Extension Compromises 31,000 Users

A recent investigation by Socket has unveiled a troubling security breach linked to a malicious Twitch browser extension that has been forwarding live OAuth session tokens from approximately 31,000 users to proxy servers associated with a Russian commercial bot service. This alarming discovery raises significant concerns regarding user privacy and data integrity on popular streaming platforms.

The extension in question, marketed as "Twitch Enhanced Viewer | JeetBot," was found to be available on both the Chrome Web Store and Firefox Add-ons as of September 11. At that point, it had garnered around 30,000 users on Chrome and 552 on Firefox. Surprisingly, both listings remain active at the moment of reporting, indicating a potential delay or negligence in response to the security alert.

An Unnecessary Compromise

The extension was promoted as a useful tool designed to enhance user experience by blocking advertisements, forcing video playback in 1080p resolution, and bypassing regional restrictions. However, in order to deliver these features, it rerouted Twitch video-playlist requests through the JeetBot’s proxy servers. In a concerning finding, Socket discovered that the user’s OAuth token was also sent along during this redirection process.

This OAuth token appears as a URL query parameter, which means it is stored in plaintext within the logs of the proxy server. Notably, Socket clarified that this is an account-scoped Twitch token, rather than a limited playback token. They substantiated their claims by demonstrating that the extension transmitted the same token to Twitch’s validation endpoint, solidifying suspicions about the extension’s malicious intent.

The OAuth token serves as a bearer token, which poses a significant risk. Possession of this token allows unauthorized individuals to send messages, engage in chat, and utilize channel points on behalf of the affected accounts—without needing a password or additional authentication measures.

Damaging Evidence of Malintent

One of the primary pieces of evidence supporting the assertion of malicious intent is that the extension does not actually need the OAuth token in order to function. It has been demonstrated that the extension manages playback tokens independently and manages to route traffic for a predefined list of ten Russian-language streamer channels through the same proxies without requiring any account tokens.

Earlier versions of the extension took the data collection a step further, with Socket stating that version 4.8, released back in January 2026, specifically captured tokens and sent them to a dedicated endpoint on JeetBot’s infrastructure. These early iterations also made backups on two Deno services. To further complicate the issue, these builds recorded the last token sent and implemented a five-second cooldown—an action that suggests that the receiving server was indeed storing these tokens.

Notably, the code contains comments in Russian that instruct the extension to fail silently if a token transmission fails, raising additional red flags about the developer’s intentions.

A Misleading Privacy Policy

Despite the evident breaches of user trust, the extension’s listing on the Chrome Web Store includes a data-safety section that misleadingly claims the developer neither collects nor utilizes user data, nor sells it to third parties. This is further contradicted by the linked privacy policy, which states that the extension does not collect, store, or process user data. The discrepancy between the claims made in the listing and the actual functionality of the extension reflects a troubling lack of transparency.

In light of these findings, Socket has advised users to promptly remove the extension from their browsers, disconnect all sessions in their Twitch account settings, and go through the re-authentication process. This measure would invalidate any accessed tokens and potentially thwart further unauthorized access.

Security Alerts Issued

Socket has further alerted security teams to treat browser extensions that have host permissions over authenticated services, especially when combined with proxy destinations run by third parties, as potential risks for credential exposure. The implications of this data breach highlight the need for more stringent scrutiny of browser extensions that users commonly utilize.

Both Google, Mozilla, and Twitch were contacted for comments on the investigation and its findings. As of yet, no responses have been received, but updates to the article will be made in the event that any of these companies release statements regarding this alarming situation.

In a landscape where digital security remains paramount, this incident underscores the necessity for users to be cautious about the tools they install and use. Awareness and vigilance are crucial to safeguarding against such insidious threats.

Source link

Exit mobile version