A malicious browser extension on Twitch has compromised nearly 31,000 users’ sensitive information, leaving them vulnerable to potential attacks. The extension, which was masquerading as a legitimate tool for streamers, had been secretly collecting OAuth tokens from affected users, allowing its creators to access their sensitive data and potentially take control of their accounts.
The malicious extension, which has since been removed from the Twitch store, used a technique called cross-domain privilege escalation to gain unauthorized access to user data. This allows it to bypass security measures put in place by Twitch and access sensitive information, such as OAuth tokens, which grant users permission to interact with the platform on behalf of others. In this case, the extension was using these tokens to collect user login credentials, payment information, and other personal details.
The affected users were likely unaware that their data was being compromised due to the seamless integration of the malicious extension into Twitch’s ecosystem. This is a prime example of how seemingly harmless tools can be used for nefarious purposes, highlighting the importance of scrutinizing browser extensions and ensuring they are legitimate before installing them on our devices. The fact that this malicious extension had been active for so long without being detected suggests a lack of robust security measures in place by Twitch to protect its users.
The compromised data could potentially be used to launch targeted attacks against affected users, such as phishing or social engineering campaigns designed to extract even more sensitive information. In the worst-case scenario, attackers may use this information to take control of user accounts, compromising their online presence and potentially allowing them to spread malware or engage in other malicious activities.
Twitch has taken swift action to remove the malicious extension from its store, but users must remain vigilant and regularly review their browser extensions for any suspicious activity. This is a stark reminder that even seemingly reputable platforms can be vulnerable to security breaches if not properly secured, emphasizing the need for robust cybersecurity measures to protect our online identities.
In light of this incident, it’s essential for Twitch users to review their account settings and ensure that all installed extensions are legitimate and have been recently updated. Regularly monitoring browser extensions for any suspicious activity or behavior can help prevent similar incidents in the future.
Source: The Hacker News — 2026-09-14