A security flaw in a Twitch browser extension has compromised the OAuth tokens of nearly 31,000 users, sending them to proxy servers linked to a Russian bot service. The extension, ‘Twitch Enhanced Viewer | JeetBot,’ is available on both the Google Chrome Web Store and Mozilla Firefox Add-Ons store. It promises enhanced streaming capabilities, including 1080p quality for restricted regions.
Vulnerabilities in JeetBot Extension
The ‘Twitch Enhanced Viewer | JeetBot’ extension, developed by HISHIMIRO/jeetbot.cc, was found to forward OAuth tokens to the operator’s proxy servers. According to security researcher Kush Pandya from Socket, the extension uses a query parameter to transmit these tokens for every channel viewed, sparing only a select group of ten Russian channels. This information could enable unauthorized access to users’ private Twitch data, including chats and account settings.
The extension’s vulnerability stems from its method of routing Twitch’s video-playlist requests through these proxy servers, attaching the user’s token in the process. This effectively exposes sensitive user information, which is logged in cleartext on the proxy server. Despite the serious security implications, the extension remains available for download.
Details of the Token Exposure
The exposed OAuth tokens grant substantial access to user accounts, allowing actions such as reading and sending whispers, posting in chat, and spending channel points. This raises significant privacy concerns, given that the tokens are bearer credentials that do not require a password or second-factor authentication for access.
The extension’s earlier versions handled the tokens even less securely, posting them to a specific endpoint on the operator’s server. This was changed in the latest update, version 85.8.7 for Firefox, which now retrieves playlists without sending tokens to the proxy servers. However, users must update their extensions to benefit from these changes.
Steps Taken to Address the Issue
JeetBot’s developer, Aleksandr Popov, has acknowledged the security flaw and taken steps to mitigate the risk. The latest update for Firefox and an impending review for Chrome aim to resolve the issue by altering how playlists are accessed. Users are advised to update to version 85.8.7 or later to prevent further token transmission.
The developer also suggests temporarily disabling the extension to stop any ongoing token exposure. Nevertheless, previously transmitted tokens remain vulnerable. Until further notice, users are encouraged to stay vigilant and ensure their extensions are updated promptly.
The incident highlights the ongoing challenges in securing browser extensions and the potential risks they pose to user privacy. As the situation unfolds, The Hacker News is awaiting further comments from both Socket and the developer to provide additional insights into this security breach.
