HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

Malicious Twitch Browser Extension Leaks OAuth Tokens from Nearly 31,000 Users

A browser extension named Twitch Enhanced Viewer | JeetBot harvested OAuth tokens from about 31 k Twitch accounts and sent them to proxy servers run by a Russian bot service. The leak demonstrates the need for continuous third‑party risk monitoring and robust access‑control evidence to satisfy audit requirements.

Verisq™ Intelligence · 📅 September 14, 2026 · 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Malicious Twitch Browser Extension Leaks OAuth Tokens from Nearly 31,000 Users

What Happened – A cross‑store browser extension called Twitch Enhanced Viewer | JeetBot was discovered to be harvesting OAuth access tokens from roughly 31 k Twitch accounts. The stolen tokens were sent to proxy servers operated by a Russian commercial bot service, giving the attackers the ability to act on behalf of the compromised users.

Why It Matters for Trust & Control Assurance

  • The incident illustrates the risk of unmanaged third‑party software that can bypass an organization’s access‑control boundaries.
  • Continuous vendor‑risk monitoring and evidence collection are essential to prove due‑diligence and maintain a defensible audit trail.
  • Demonstrable oversight of external components (e.g., browser extensions) satisfies a core control objective that maps to many frameworks (access‑control, supply‑chain risk, and monitoring).

Who Is Affected – Streaming platforms (Twitch), their content creators, and any downstream services that rely on the compromised OAuth tokens.

Recommended Actions

  • Inventory all browser extensions and third‑party add‑ons used by staff and by any public‑facing applications.
  • Enforce least‑privilege scopes for OAuth tokens and rotate them immediately for affected accounts.
  • Deploy a continuous third‑party risk program that monitors marketplace listings, validates developer identities, and captures evidence of compliance.

Technical Notes – The extension was distributed via the Chrome Web Store and Mozilla Firefox Add‑Ons store. It exfiltrated tokens through HTTP requests to proxy servers controlled by the bot service; no CVE was involved, and the attack vector was a malicious third‑party dependency. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →