Researchers at Socket found that a browser extension called "Twitch Enhanced Viewer," installed by roughly 30,000 Chrome and Firefox users, secretly forwards users' live Twitch session tokens to proxy servers run by a Russian-language bot service. Those tokens let anyone holding them act on the account without the password or two-factor authentication. The extension's advertised features, like ad blocking, forced 1080p, and region unlocking, are real and serve as cover: to deliver them it routes Twitch's video requests through operator-controlled proxies and skims the authentication token along the way. Earlier versions posted stolen tokens to a dedicated collection endpoint. Affected users should remove it and sign out of all Twitch sessions.
Researchers at Check Point analyzed JSCeal, malware compiled into a hard-to-analyze bytecode format that steals browser cookies and authentication tokens to hijack accounts. By replaying stolen session cookies, an attacker can access a victim's Google account without the password or a second factor, and the malware also grabs saved passwords, autofill data, and OAuth tokens to automate further account access. It additionally targets cryptocurrency wallets and platforms and includes keylogging, screenshots, and messaging-session theft. The compiled format and layered obfuscation push it outside analysts' usual tooling, though Check Point released a deobfuscator. It is a reminder that stolen session cookies quietly defeat passwords and multi-factor authentication alike.
A commercial phishing-as-a-service toolkit called Mirage2FA has hit around 4,500 organizations by abusing legitimate Microsoft 365 login flows to steal passwords and session cookies and bypass two-factor authentication. Because it captures the session cookie after a real login completes, the attacker inherits an authenticated Microsoft 365 session and any single-sign-on connected services, defeating multi-factor authentication. Researchers at ANY.RUN linked the campaign to more than 9,000 potential compromise events and found that nearly half of targeted addresses may have been affected, with most victims in the United States across technology, manufacturing, and education. Hijacking one session can expand into connected apps and internal workflows.
Jamf detailed a new macOS information stealer, AmnesiaStealer, spread through ClickFix lures that trick users into running a command from a fake download page. Beyond harvesting the login password, keychain, browser data, and cryptocurrency wallets, it includes a module that clones the victim's Chromium browser profile, including its logged-in state, into a hidden browser on the infected Mac and gives the attacker live remote control of it through the browser's debugging protocol. Because the session runs on the victim's own device with their real identifiers, this lets the attacker use authenticated accounts while sidestepping multi-factor authentication. Jamf calls it the first macOS malware to combine profile cloning with live remote browser control.