Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: oauth-token-theft (2 articles)Clear

Malicious Twitch extension leaks live session tokens from about 30,000 users

Researchers at Socket found that a browser extension called "Twitch Enhanced Viewer," installed by roughly 30,000 Chrome and Firefox users, secretly forwards users' live Twitch session tokens to proxy servers run by a Russian-language bot service. Those tokens let anyone holding them act on the account without the password or two-factor authentication. The extension's advertised features, like ad blocking, forced 1080p, and region unlocking, are real and serve as cover: to deliver them it routes Twitch's video requests through operator-controlled proxies and skims the authentication token along the way. Earlier versions posted stolen tokens to a dedicated collection endpoint. Affected users should remove it and sign out of all Twitch sessions.

Check
Remove the Twitch Enhanced Viewer extension if installed, then sign out of all Twitch sessions to invalidate stolen tokens, and review installed browser extensions that hold account or broad site permissions.
Affected
Users who installed the extension on Chrome or Firefox; it forwards their live Twitch session tokens to a third party, granting account access without the password or two-factor authentication.
Fix
Restrict browser extension installation by policy, review and limit extension permissions, treat any extension that can read authenticated sessions as high-risk, and invalidate sessions if a token-stealing extension was used.

VS Code zero-day lets one click steal full-scope GitHub OAuth token via github.dev webview - PoC public, no patch yet

Security researcher Ammar Askar has released exploit code for an unpatched VS Code zero-day that lets attackers steal GitHub OAuth tokens with a single click. The flaw abuses VS Code's sandboxed webview message-passing system: malicious JavaScript in a webview simulates keypresses in the main editor to install a malicious extension that captures the GitHub OAuth token github.com POSTs to github.dev. The token is not scoped to a single repo - it grants full access to every private repository the victim can reach. No CVE has been assigned and there is no patch. Users can mitigate by clearing github.dev cookies and on-device site data, which restores the sign-in prompt.

Check
Inventory developer machines using VS Code and github.dev. Warn developers not to click untrusted links that open github.dev. Audit installed VS Code extensions for unfamiliar additions.
Affected
VS Code users who authenticate to github.dev. The leaked GitHub OAuth token is unscoped, granting full access to every private repository the victim can reach. No patch or CVE yet.
Fix
Until patched: clear github.dev cookies and on-device site data so the sign-in prompt reappears. Treat unsolicited github.dev links as hostile. Rotate GitHub tokens if exposure is suspected.