$ techbeacon▋
Threats

Security Flaw Found in Popular Twitch Viewer Extension That Leaks OAuth Tokens

Security Flaw Found in Popular Twitch Viewer Extension That Leaks OAuth Tokens

A browser add‑on marketed as Twitch Enhanced Viewer | JeetBot has been identified as transmitting users' Twitch OAuth session tokens to an external commercial bot service, raising serious privacy and security concerns for the platform's community.

The extension, which is listed in the official Chrome Web Store and Mozilla Firefox Add‑ons repository, was discovered to capture the authentication token that Twitch issues to logged‑in users. Instead of keeping the token local to the browser, the code forwards it to a third‑party server that operates a bot service, effectively granting the service full access to the victim's Twitch account.

OAuth tokens are designed to act as proof of identity for web applications, allowing them to perform actions on behalf of the user without exposing passwords. When such a token is leaked, the holder can read private data, modify channel settings, or even broadcast streams under the compromised account. Security researchers who examined the extension’s network traffic reported that each token is sent in plain‑text HTTP requests, making interception trivial for any observer on the same network.

While the extension’s description promotes features such as enhanced chat visibility and custom emotes, its hidden behavior was not disclosed to users. The extension’s presence in official stores underscores the challenges platform owners face in vetting third‑party software. Twitch has not yet issued a formal statement, but the company’s developer guidelines explicitly forbid the collection of authentication credentials by extensions.

Cyber‑security experts advise users to remove the add‑on immediately, revoke any OAuth authorizations granted to the suspicious service via Twitch’s security settings, and enable two‑factor authentication for added protection. The incident also serves as a reminder for developers to scrutinize the permissions requested by browser extensions and for browsers to enforce stricter review processes for apps that interact with high‑value services.

The findings were first reported by BleepingComputer, prompting both Google and Mozilla to review the extension’s compliance with their policies. If the extension is found to be in violation, it could be delisted from the stores, and affected users may receive guidance on securing their accounts. Meanwhile, the broader community is watching closely as this case highlights the ongoing tension between convenient third‑party tools and the imperative to safeguard user credentials.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related