Malicious Twitch Browser Extension Exposes OAuth Tokens of Nearly 31,000 Users
Thionne_WTZ · x · 2026-09-15
A malicious Twitch browser extension leaked OAuth tokens for nearly 31,000 users, highlighting supply chain risks hidden in seemingly harmless third-party tools. The post argues that autonomous security scanning is critical to continuously surface such vulnerabilities before they are exploited.
Related event: Malicious Chrome Extension Steals OAuth Tokens From 30,000 Twitch Users(2 posts)→
More from Safety
- METR self-audit passes most of its own criteria, fails only on conflict-of-interest disclosure — kevinnbass · 2026-09-15
- Big Tech's AI slowdown pact: safety agreement or outright cartel? — The Verge AI · 2026-09-15
- Amodei proposes embedded safety evaluators; Altman and Musk endorse the plan — Miles_Brundage · 2026-09-15
- Kapoor and Narayanan's 13,000-word essay reframes AI loss-of-control incidents — sayashk · 2026-09-15
- Miles Brundage warns of wave of fake DMCA spear phishing attacks on X — Miles_Brundage · 2026-09-15
- New 13,000-word essay: AI safety should bet on control and governance over alignment — sayashk · 2026-09-15