Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens
Overview
A newly discovered malicious Twitch browser extension has been found to be forwarding OAuth tokens from users to a Russian bot service. This incident affects around 31,000 Twitch users, putting their accounts at risk. OAuth tokens are critical for accessing user accounts without needing to share passwords, so their exposure can lead to unauthorized access and potential account takeovers. Users of the affected extension should immediately remove it from their browsers, change their Twitch passwords, and consider revoking any third-party access to their accounts. This incident serves as a reminder for users to be cautious about the extensions they install and to regularly monitor their account activity for any suspicious behavior.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Twitch users, malicious browser extension
- Action Required: Remove the malicious extension, change Twitch passwords, revoke third-party access to Twitch accounts.
- Timeline: Newly disclosed
Original Article Summary
Socket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot service
Impact
Twitch users, malicious browser extension
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Remove the malicious extension, change Twitch passwords, revoke third-party access to Twitch accounts
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Critical.