Twitch extension with 30K installs leaks user login tokens
A popular browser extension for Twitch, used by over 30,000 people, was found to be secretly sending users' login credentials to servers controlled by a commercial bot service. The extension, named Twitch Enhanced Viewer JeetBot, is available on both the Chrome Web Store and Firefox Add-ons store. Security researchers at Socket discovered that the tool captures a user's Twitch OAuth session token and forwards it as a plain text parameter in network requests to proxy servers operated by JeetBot, a Russian-language streaming bot service. The OAuth token acts as a bearer credential, allowing anyone who possesses it to access a user's Twitch account without needing a password or two-factor authentication. This access includes reading private whispers, sending chat messages, and spending channel points. The token is transmitted for every channel a user watches, with the exception of a hardcoded list of ten Russian-language streamer channels. The developer, identified as Cyprus-based Aleksandr Popov, has released a fix for the Firefox version of the extension. An alert on the JeetBot documentation page states that version 85.8.7 no longer sends tokens to the proxy servers.