UNTERNEHMEN & BRANCHE

Twitch extension compromises 31,000 users

Twitch extension compromises 31,000 users

A malicious Twitch extension leaked OAuth tokens from nearly 31,000 users to Russian proxy servers.

A recently discovered malicious browser extension for Twitch has compromised the OAuth tokens of nearly 31,000 users. The extension, known as "Twitch Enhanced Viewer | JeetBot," was offered in various browser stores and has proven to be dangerous. The tokens were forwarded to proxy servers operated by a Russian commercial bot service.

The extension was listed under the developer name HISHIMIRO on the Google Chrome Web Store and Mozilla Firefox Add-Ons platforms. Users who had installed this extension are now potentially at risk, as their credentials and personal information may have fallen into the wrong hands. The vulnerability was discovered by experts who analyzed the functionality of the extension.

Details of the Vulnerability

The malicious extension managed to infiltrate users' browsers by presenting itself as a useful feature. The OAuth tokens it intercepted are crucial for accessing the Twitch platform and allow third parties to act on behalf of users. This could lead to unauthorized access to accounts and potential abuse.

Security researchers found that the extension was available not just in one, but in several browser stores, which facilitated its spread and installation. Users who downloaded the extension should urgently check their accounts and change their credentials if necessary to protect themselves from potential attacks.

The discovery of this vulnerability raises questions about the security of browser extensions. Many users may not be aware of the risks associated with installing third-party software. The fact that such an extension has affected so many users highlights the importance of being cautious when selecting extensions.

Reactions and Measures

The reaction of the Twitch community to this security threat has been mixed. Some users expressed their concerns about the platform's security and urged Twitch to take action to prevent such incidents in the future. Other users have already checked their accounts and taken security measures to protect themselves from potential attacks.

Twitch has not yet issued an official statement regarding this incident. It remains to be seen whether the platform will implement additional security measures to protect its users. Security researchers recommend that all users who installed the extension immediately check their accounts and change their credentials if necessary.

The malicious extension "Twitch Enhanced Viewer | JeetBot" is an example of the growing threats in the field of online security. Users should be aware of the risks and ensure that they only install trusted extensions. The security situation on the internet remains tense, and it is important to stay vigilant.

comment Kommentare (0)

Noch keine Kommentare. Schreiben Sie den ersten!

Kommentar hinterlassen