31,000 Twitch users hit by malicious browser extension — OAuth tokens leaked via Russian proxy network

https://cdn.mos.cms.futurecdn.net/33ooyG4FCgVjDs8W6RpowC-2000-80.jpg
  • Socket found Twitch extension JeeBot harvesting OAuth tokens via proxy servers
  • Tokens excluded only for 10 Russian streamer channels, suggesting deliberate design
  • Developer issued fixes, but users should revoke exposed tokens for safety

A browser extension for Twitch was harvesting people’s OAuth tokens and sending them to a Russian-owned server. The move was deliberate, but whether or not it was malicious is not that easily determined.

Security researchers Socket recently found an extension for both Chrome and Firefox, called “Twitch Enhanced Viewer | JeeBot”. It has roughly 30,000 users on Chrome, and some 600 on Firefox.

On the Chrome Web Store, it is advertised as a “modern tool for streamers and viewers who value quality, convenience, and control.” Apparently, it makes streaming and viewing clearer, allows viewing content in 2K, hides banner ads and unwanted elements, and even offers an AI bot to make it easier to interact with the...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more