Close Menu
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Twitch extension leaks OAuth tokens affecting 31,000 users

September 14, 2026

Nigeria faces 45% surge in cyber attacks weekly

September 14, 2026

CISA Flags Critical Ray Flaw for Browser-Based RCE Exploits

September 13, 2026
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance
Home » Twitch extension leaks OAuth tokens affecting 31,000 users
Most Read

Twitch extension leaks OAuth tokens affecting 31,000 users

Staff WriterBy Staff WriterSeptember 14, 2026No Comments2 Mins Read0 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

Top Highlights

  1. A Twitch browser extension named "JeetBot" has leaked approximately 31,000 users’ OAuth tokens to Russian-controlled proxy servers, enabling potential unauthorized access to chat, private messages, and account settings.
  2. The extension retrieves OAuth tokens by embedding them in URL query parameters sent to operator-controlled proxies, which logs these tokens in plaintext, exposing sensitive credentials.
  3. Although an update (version 85.8.7) has addressed the token leakage, many users remain vulnerable until they upgrade, risking account hijacking, spying, or malicious activity.

Threat Overview, Techniques, and Targets

A malicious Twitch browser extension called “Twitch Enhanced Viewer | JeetBot” has leaked OAuth tokens of nearly 31,000 users. The extension appears legitimate and promises enhanced viewing and streaming features. However, it secretly captures user tokens and sends them to proxy servers run by a Russian bot service. The extension embeds code that recovers OAuth tokens and forwards them via URLs with an “&auth=” query parameter. This process is part of redirecting Twitch video playlist requests. The extension is available on both Google Chrome Web Store and Mozilla Firefox Add-Ons, and both are still accessible. The extension targets Twitch users, especially streamers and viewers seeking features like ad-free content and region unlocking. It also accesses users’ chat, private messages, and account settings by capturing OAuth tokens. The attacker’s infrastructure is operated by a service that has broad permissions over Twitch, Kick, and VK-Live.

Impact, Security Risks, and Remediation

The leak of OAuth tokens exposes users to significant security risks. Anyone with a token can access a user’s Twitch account. This includes reading and sending private messages, chatting, or spending channel points. In addition, tokens in logs can be stolen and misused. The extension’s operator runs a bot SaaS that relays live sessions through its infrastructure. Although the developers have issued an update (version 85.8.7) to fix the problem, older versions still send tokens. Users are advised to update the extension to the latest version immediately. If an update is not yet available, users should disable the extension temporarily. It is also important to remember that disabling or updating the extension does not revoke previously transmitted tokens. For detailed guidance and further assistance, users should consult the relevant vendor or authority.

Stay Ahead with the Latest Tech Trends

Learn how the Internet of Things (IoT) is transforming everyday life.

Discover archived knowledge and digital history on the Internet Archive.

ThreatIntel-V1

CISO Insights cyber risk Cybersecurity MX1 risk management Threat Management
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNigeria faces 45% surge in cyber attacks weekly
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

Nigeria faces 45% surge in cyber attacks weekly

September 14, 2026

August 2026: Rise of AI-Enhanced Dark Web Threat Actors

September 13, 2026

Attackers Exploit Passkey Phishing to Hijack Microsoft Accounts

September 13, 2026

Comments are closed.

Latest Posts

CISA Flags Critical Ray Flaw for Browser-Based RCE Exploits

September 13, 2026

TWINLOOT Exploits SharePoint and Teams to Steal Credentials and Lateral Movement

September 10, 2026

Windchill Web Shell Exposes Credentials and Maps Engineering Data

September 7, 2026

SilkParasite Espionage Campaign Launches Five New RATs Against Central Asian Governments

September 4, 2026
Don't Miss

Nigeria faces 45% surge in cyber attacks weekly

By Staff WriterSeptember 14, 2026

Summary Points Nigeria experienced a 45% surge in cyber attacks, averaging 4,906 weekly incidents in…

August 2026: Rise of AI-Enhanced Dark Web Threat Actors

September 13, 2026

Attackers Exploit Passkey Phishing to Hijack Microsoft Accounts

September 13, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Twitch extension leaks OAuth tokens affecting 31,000 users
  • Nigeria faces 45% surge in cyber attacks weekly
  • CISA Flags Critical Ray Flaw for Browser-Based RCE Exploits
  • August 2026: Rise of AI-Enhanced Dark Web Threat Actors
  • Attackers Exploit Passkey Phishing to Hijack Microsoft Accounts
About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Twitch extension leaks OAuth tokens affecting 31,000 users

September 14, 2026

Nigeria faces 45% surge in cyber attacks weekly

September 14, 2026

CISA Flags Critical Ray Flaw for Browser-Based RCE Exploits

September 13, 2026
Most Popular

CISA Alerts: Critical Vulnerability in Splunk Enterprise Under Active Attack

June 19, 2026178 Views

Gefährliche Angriffe: Wie Cyberkriminelle Ihre Identität angreifen

January 29, 2026176 Views

Salesforce Disables Klue App After Data Breach from Token Abuse

June 19, 2026175 Views

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025

Categories

  • Compliance
  • Cyber Updates
  • Cybercrime and Ransomware
  • Editor's pick
  • Emerging Tech
  • Events
  • Featured
  • Insights
  • Most Read
  • Threat Intelligence
  • Uncategorized
© 2026 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.