Twitch Extension Hijacks Tokens, Exposing Tens of Thousands of Users
A security firm named Socket has uncovered a malicious browser extension for Twitch that silently captured and relayed users' OAuth authentication tokens to a bot service operating out of Russia, affecting roughly 31,000 accounts, according to a report first published by Infosecurity Magazine.
OAuth tokens act as digital keys that let third‑party applications act on a user's behalf within the Twitch ecosystem. When a token is compromised, an attacker can stream, modify channel settings, read private messages, or even withdraw revenue, making the protection of these credentials a critical part of platform security.
The extension in question appeared to function as a typical utility for viewers, offering features such as chat enhancements and overlay controls. Behind the scenes, however, it injected hidden network calls that transmitted the captured tokens to a remote server controlled by the bot network. The traffic was obfuscated through standard HTTPS requests, making detection difficult for casual users and many security tools.
Socket's researchers traced the data flow by monitoring outbound requests from the extension and cross‑referencing the destination IP addresses with known malicious infrastructure. Their findings were then shared with Twitch and the broader security community, prompting Infosecurity Magazine to publish the details. The firm has not disclosed the exact name of the extension, citing ongoing investigations and the need to prevent further exploitation.
With the tokens in hand, threat actors could potentially hijack Twitch accounts, post unauthorized content, or leverage the compromised credentials for broader phishing campaigns. While no large‑scale abuse has been publicly confirmed, the sheer number of affected users raises concerns about possible account takeovers and the erosion of trust in third‑party Twitch tools.
Twitch responded by revoking the compromised tokens, removing the offending extension from its approved list, and urging users to delete the extension, change their passwords, and re‑authenticate any remaining applications. The incident underscores the growing risk posed by browser extensions that operate with elevated permissions, prompting calls for stricter vetting processes and more transparent permission models across streaming platforms.
Comments (0)
Be the first to comment.
Join the discussion