Trending: On-device modelsSearch
iHeartGeek
iTECH

31,000 Twitch Users Hit by Malicious Extension

A malicious browser extension reportedly exposed OAuth tokens belonging to around 31,000 Twitch users through a Russian proxy network.

Twitch security artwork illustrating the malicious browser extension report

A malicious browser extension reportedly exposed OAuth tokens belonging to around 31,000 Twitch users through a Russian proxy network.

TechRadar reports that the extension, identified as JeeBot, was used to harvest Twitch authentication tokens. The report says the tokens were routed through proxy servers and that only ten Russian streamer channels were excluded.

What’s actually going on

OAuth tokens can allow a connected service to act on a user’s behalf without requiring a password each time. If those tokens are stolen, attackers may be able to access or manipulate account functions until the tokens are revoked.

TechRadar reports that the incident involved a malicious browser extension called JeeBot and the harvesting of Twitch authentication tokens. Independent technical confirmation and guidance from the affected services remain important when assessing the report.

Why you should care

Browser extensions sit close to the accounts people use every day, which makes a malicious or compromised add-on particularly dangerous. Remove untrusted extensions, review connected applications and revoke suspicious sessions or tokens.

Our opinion

A leaked password is obvious; a stolen token can be much sneakier. Verify the technical evidence first, then tell users exactly what they need to revoke.

What we know
  • TechRadar reports a malicious extension named JeeBot
  • The report says around 31,000 Twitch users were affected
  • Primary technical confirmation remains required