← Back to Feed
Twitch extension with 30K installs exposes users’ OAuth tokens
September 14, 2026 · BleepingComputer · Severity: MEDIUM
A malicious Twitch browser extension with 30,000 installs has been caught leaking OAuth authentication tokens, potentially compromising user accounts and linked third-party services through persistent token theft. 📌 **Analyst Note:** This is the second Twitch extension token theft campaign documented in September 2026, suggesting an organized effort targeting Twitch's ecosystem. Users should be extremely cautious about granting OAuth permissions to any third-party extension.
Key Takeaways
- A malicious Twitch browser extension with approximately 30,000 installs has been discovered leaking user OAuth authentication tokens.
- The extension masqueraded as a legitimate Twitch enhancement while silently exfiltrating tokens to attacker-controlled servers.
- Users should review and revoke OAuth tokens granted to third-party browser extensions and enable hardware-based two-factor authentication.