55
30
47
30
42
55
Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Malicious 'Twitch Enhanced Viewer | JeetBot' browser extension stole live OAuth session tokens from roughly 31,000 Chrome and Firefox users.
Socket.dev found the cross-store extension 'Twitch Enhanced Viewer | JeetBot' rerouted Twitch playlist requests through operator-controlled proxies, attaching the victim's account-level OAuth token as a URL parameter where it could be logged in cleartext. About 30,000 Chrome and 552 Firefox installs were exposed, with tokens forwarded for nearly every watched channel to infrastructure tied to a Russian commercial bot service. The stolen bearer token enables chat, whisper, account-setting access and channel-point spending without the password or 2FA.
52
55
42
55
55
55
55
30
30
30
55
42
55
30
30
Insight to sell and support the Byos family of patented plug-and-play Secure Endpoint Edge solutions
30
55
42
30
30
55
55
55
42
30
42
30
42
55
60
30
55
42
55