Twitch extension with 30K installs exposes users’ OAuth tokens
A Twitch extension with over 30,000 installs captures user OAuth tokens and sends them through proxy servers, exposing user data.
Intelligence analysis by Qwen 2.5 (3B)

A security analysis reveals that a popular Twitch browser extension is leaking user OAuth tokens, potentially exposing sensitive information.
A Twitch extension that many people use is secretly taking their login information and sending it to a server. This could let bad guys pretend to be the people using the extension and get into their Twitch accounts.
Analysis
The malicious extension appends the token as an &auth= query parameter to redirected proxy requests, making it visible in the proxy server’s request logs. This exposes the OAuth tokens, which can be used to access user accounts and personal data. The extension’s developers have acknowledged the security risk and recommend users to remove the extension and re-authenticate their accounts.
Key points
- A popular Twitch extension with over 30,000 installs captures user OAuth tokens
- The extension sends OAuth tokens through proxy servers, exposing user data
- Users are advised to remove the extension and re-authenticate their accounts
Users can protect themselves by removing the extension and re-authenticating their accounts to ensure their login information is secure.
If users don’t remove the extension and re-authenticate, their login information could be at risk of being stolen by bad guys.



