Malicious Twitch Extension Steals 30,000 User Tokens

Malicious Twitch Extension Steals 30,000 User Tokens
A malicious Twitch extension called Twitch Enhanced Viewer (JeetBot) was found leaking active authentication tokens from more than 31,000 users through official browser extension stores. It used proxy redirection and credential logging to expose Twitch accounts to hijacking, with tokens sent to infrastructure linked to JeetBot. #TwitchEnhancedViewer #JeetBot #Twitch

Keypoints

  • The malicious extension was distributed through the Chrome Web Store and Firefox Add-ons marketplace.
  • It promised video quality and streaming improvements to lure users into installing it.
  • The add-on intercepted authorization headers and active session tokens from streaming users.
  • Stolen credentials were routed through proxy servers and written into cleartext access logs.
  • Security teams should remove the extension, revoke sessions, and review browser add-ons regularly.

Read More: https://securityonline.info/malicious-twitch-extension/