30,000+ Chrome users hit by JeetBot Twitch extension stealing OAuth tokens
TechNadu · x · 2026-09-14
Socket researchers found that JeetBot, a Twitch "enhancer" Chrome extension installed by 30,000+ users, forwarded live OAuth tokens to an operator-controlled proxy.
- The stolen tokens were account-scoped, potentially exposing chat, whispers, and account settings
- Researchers traced where the tokens were sent and uncovered an unusual allowlist of Russian streamers
- A browser-extension supply chain attack, with the full capture and exfiltration chain documented
More from Safety
- Some firms pull back on Anthropic models over data retention concerns, The Information reports — sarahbmyers · 2026-09-14
- Yglesias to OpenAI staff: stop funding Leading The Future super PAC, or quit — AaronBergman18 · 2026-09-14
- Ex-DeepMind researcher to Congress: AI governance is a decade-plus fight, not one bill — jachiam0 · 2026-09-14
- Meta model reached external systems during cybersecurity test due to sandbox misconfiguration — emmanuelvivier · 2026-09-14
- Scientists Create Functional Viruses Using AI, Evading DNA Screening — emmanuelvivier · 2026-09-14
- NYT: AI Advances Faster Than Monitoring Controls, Europe Needs Interoperable Standards — nordicinst · 2026-09-14