Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: session-hijacking (4 articles)Clear

Malicious Twitch extension leaks live session tokens from about 30,000 users

Researchers at Socket found that a browser extension called "Twitch Enhanced Viewer," installed by roughly 30,000 Chrome and Firefox users, secretly forwards users' live Twitch session tokens to proxy servers run by a Russian-language bot service. Those tokens let anyone holding them act on the account without the password or two-factor authentication. The extension's advertised features, like ad blocking, forced 1080p, and region unlocking, are real and serve as cover: to deliver them it routes Twitch's video requests through operator-controlled proxies and skims the authentication token along the way. Earlier versions posted stolen tokens to a dedicated collection endpoint. Affected users should remove it and sign out of all Twitch sessions.

Check
Remove the Twitch Enhanced Viewer extension if installed, then sign out of all Twitch sessions to invalidate stolen tokens, and review installed browser extensions that hold account or broad site permissions.
Affected
Users who installed the extension on Chrome or Firefox; it forwards their live Twitch session tokens to a third party, granting account access without the password or two-factor authentication.
Fix
Restrict browser extension installation by policy, review and limit extension permissions, treat any extension that can read authenticated sessions as high-risk, and invalidate sessions if a token-stealing extension was used.

JSCeal malware steals session cookies to log into Google without the password

Researchers at Check Point analyzed JSCeal, malware compiled into a hard-to-analyze bytecode format that steals browser cookies and authentication tokens to hijack accounts. By replaying stolen session cookies, an attacker can access a victim's Google account without the password or a second factor, and the malware also grabs saved passwords, autofill data, and OAuth tokens to automate further account access. It additionally targets cryptocurrency wallets and platforms and includes keylogging, screenshots, and messaging-session theft. The compiled format and layered obfuscation push it outside analysts' usual tooling, though Check Point released a deobfuscator. It is a reminder that stolen session cookies quietly defeat passwords and multi-factor authentication alike.

Check
Treat session cookies as sensitive credentials: monitor endpoints for access to browser cookie databases and suspicious script-to-runtime execution chains, and shorten session lifetimes so stolen cookies expire sooner.
Affected
Users whose browsers are infected by this stealer; theft of session cookies and OAuth tokens lets attackers replay authenticated Google sessions without the password or second factor, and reach crypto accounts.
Fix
Bind sessions to devices where supported, expire and revoke sessions on anomalies, deploy endpoint detection for cookie theft and in-memory browser attacks, and monitor for session replay from unfamiliar locations.

Mirage2FA phishing service hijacks Microsoft 365 sessions and bypasses two-factor

A commercial phishing-as-a-service toolkit called Mirage2FA has hit around 4,500 organizations by abusing legitimate Microsoft 365 login flows to steal passwords and session cookies and bypass two-factor authentication. Because it captures the session cookie after a real login completes, the attacker inherits an authenticated Microsoft 365 session and any single-sign-on connected services, defeating multi-factor authentication. Researchers at ANY.RUN linked the campaign to more than 9,000 potential compromise events and found that nearly half of targeted addresses may have been affected, with most victims in the United States across technology, manufacturing, and education. Hijacking one session can expand into connected apps and internal workflows.

Check
Move toward phishing-resistant authentication such as passkeys or hardware security keys, since attacker-in-the-middle kits like this defeat ordinary two-factor by stealing the session after login.
Affected
Microsoft 365 organizations relying on passwords plus standard two-factor authentication; Mirage2FA steals the post-login session cookie to hijack authenticated sessions and single-sign-on services, extending access well beyond the first account.
Fix
Adopt phishing-resistant multi-factor authentication, shorten session lifetimes and bind sessions to devices, monitor for anomalous token use and impossible-travel sign-ins, and revoke sessions on suspicion rather than trusting a successful login.

AmnesiaStealer hijacks live macOS browser sessions to ride past logins

Jamf detailed a new macOS information stealer, AmnesiaStealer, spread through ClickFix lures that trick users into running a command from a fake download page. Beyond harvesting the login password, keychain, browser data, and cryptocurrency wallets, it includes a module that clones the victim's Chromium browser profile, including its logged-in state, into a hidden browser on the infected Mac and gives the attacker live remote control of it through the browser's debugging protocol. Because the session runs on the victim's own device with their real identifiers, this lets the attacker use authenticated accounts while sidestepping multi-factor authentication. Jamf calls it the first macOS malware to combine profile cloning with live remote browser control.

Check
Warn Mac users never to paste and run commands from a web page or fake download prompt, and treat unexpected browser sessions or new hidden browser processes as a compromise indicator.
Affected
macOS users tricked by ClickFix lures into running the loader; AmnesiaStealer steals credentials and wallets and clones logged-in browser sessions for live remote use, letting attackers bypass multi-factor authentication.
Fix
Block known ClickFix infrastructure, educate users against pasted-command prompts, keep macOS and security tooling current, and monitor for browsers launched in debugging mode and unexpected headless browser activity.