OVERCLOCK.news
streaming

Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian…

BlueskyXRedditMail
Revised 1 change recorded since we first saw this
Feedburner.Com 2 versions
  1. Current Headline changed

    The headline was rewritten.

    Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

    A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store - Chrome -

  2. As first published

    Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

    A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store - Chrome -

Read the current version at Feedburner.Com →

Versions are compared on the headline and summary the publisher puts in their feed. An edit to the body of an article that leaves both untouched will not appear here.

Why am I seeing this Single-sourced — only Feedburner has this

Only Feedburner has this. It is here on that single source, so read it as one outlet's reporting until somebody else confirms it.

Single-sourced. No second organisation has confirmed it yet.

Link-outLink-out, because only one organisation carries it and no first-party source is on it. Link-out means we point at the publisher and say nothing of our own.

Blended score 0.225 — every figure below is computed, none of it is editorial.
FactorWeightScore ContributionWhere it came from
Corroborationleads 0.35 0.39 +0.135 60% 1 independent org on the story. Tier-3 aggregators never corroborate — they can show something is circulating, never that it is true.
Source trust 0.25 0.36 +0.089 40% Feedburner is the highest-trust source on this story. Trust is taken from the best source, not averaged.
Pickup rate 0.20 0.00 +0.000 0% One counted organisation, so there is no spread to measure — nothing has picked this up to set a rate.
Freshness 0.20 0.00 +0.000 0% Halves every 10 hours from the newest item on the story. This is the only factor that rewards a story for nothing more than being recent.

Corroboration counts distinct organisations, once each, and only from tiers 1 and 2. Freshness halves every 10 hours, so this ranking is a snapshot and will differ at the next build.

Read the full article at Feedburner →

What happened

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store - Chrome -

1independent orgs
23story score
0velocity
36source trust
40passes seen

How this story arrived

Ordered by when each source was first observed, which is what the velocity figure is computed from. Publishers backdate; observed order does not.

  1. 01 Feedburner first seen Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

Overclock clusters coverage from independent sources and grades it automatically. The figures above are computed, not editorial. This page summarises and links to reporting by the outlets named — follow the links for the original work.