A malicious Twitch browser extension has been found to be stealing OAuth tokens from nearly 31,000 users, potentially exposing them to identity theft and other cyber attacks. The affected extension, which has been downloaded over a million times, is designed to enhance the user experience on the popular live streaming platform by providing additional features such as chat customization and notification management.
The issue stems from a vulnerability in the way the extension handles OAuth tokens, which are used to authenticate users with Twitch’s services. Once an attacker gains access to a user’s token, they can use it to gain unauthorized access to their account, making it possible for them to post malicious content, steal sensitive information, or even take control of the account altogether. This is particularly concerning given that OAuth tokens are often used as a form of two-factor authentication (2FA), which is meant to provide an additional layer of security beyond just passwords.
Twitch’s API uses something called “cross-domain privilege escalation” to allow extensions to access certain features and functionality on behalf of the user. In this case, the malicious extension exploits this feature by masquerading as a legitimate Twitch service, allowing it to bypass security checks and gain access to sensitive information. This type of attack is often referred to as an “active attack path,” because it involves actively exploiting vulnerabilities in order to breach secure systems.
The extent of the damage caused by this vulnerability is still unclear, but experts warn that users who have installed the malicious extension may be at risk for identity theft and other types of cyber attacks. Twitch has taken steps to remove the offending extension from its platform, but users are advised to take action immediately to protect themselves. This includes reviewing their account activity, changing any passwords or 2FA settings, and being cautious when installing browser extensions in the future.
The incident highlights the importance of security awareness and vigilance among users, particularly when it comes to online services that require sensitive information such as OAuth tokens. It also underscores the need for developers to prioritize security when building browser extensions and other third-party integrations with popular platforms. By taking these precautions, we can help prevent similar vulnerabilities from being exploited in the future.
In light of this incident, users are advised to regularly review their account activity and be cautious when installing browser extensions. It’s also essential to keep software up-to-date and use strong, unique passwords for all online services. By taking these simple steps, users can significantly reduce their risk of falling victim to identity theft and other types of cyber attacks.
Source: The Hacker News — 2026-09-14