Twitch users affected by malicious browser extension leaking OAuth tokens
Security researchers found a Twitch browser extension harvesting OAuth tokens from roughly 31,000 Chrome users and sending them to a Russian-owned server.

Extension design exposed user data
The tool called JeeBot was advertised as a modern utility for streamers and viewers. Researchers discovered it attached user OAuth tokens to requests sent through its own proxy servers. These logs allowed the extension to collect sensitive authentication information from affected accounts.
Specific channels were excluded from theft
Tokens were harvested from all users except for ten Russian streamer channels. This pattern suggests the developer deliberately designed the tool to avoid targeting specific regions or individuals. The extension operates on both Chrome and Firefox browsers with varying user counts.
Developer issued fixes after discovery
The developer released updates to address the security vulnerability once it was identified. Security researchers Socket reported the findings regarding the malicious data collection practices. Users are advised to revoke exposed tokens to ensure their safety.
Reported by one outlet
Only one outlet has published this. Nothing here has been checked against a second report, so read it as that outlet's account and follow the link below for the original.
Reported by
1 independent outlet. Headline as published. Links open the original report.