Home / Technology / Twitch Extension Caught Stealing User Tokens
Twitch Extension Caught Stealing User Tokens
15 Sep
Summary
- A Twitch browser extension, JeeBot, was found harvesting OAuth tokens.
- The extension routed tokens through proxy servers, excluding only Russian channels.
- Users are advised to revoke exposed tokens for security protection.
A popular Twitch browser extension, "Twitch Enhanced Viewer | JeeBot," has been discovered to be harvesting user OAuth tokens. Security researchers at Socket revealed that the extension, available for Chrome and Firefox, was sending these tokens to its own proxy servers. This action was facilitated by embedding the tokens within URL parameters during playlist retrieval.
Interestingly, the extension reportedly exempted tokens for ten specific Russian streamer channels from being forwarded. This 'hardcoded allowlist' suggests a deliberate design rather than an accidental oversight. The extension's developer has since released an updated version addressing this vulnerability.
Despite the fix, it is strongly recommended that all users of the JeeBot extension revoke their OAuth tokens immediately. This action is crucial for safeguarding account security against any potential misuse of the previously exposed information.