Popular Twitch ad blocker caught sending live account credentials to Russian proxies
cross-posted from: piefed.world/c/tech/p/1400813/popular-twitch-ad-blocker-caught-sending-live-account-credentials-to-r…
Threat Research Team identified a cross-store browser extension, “Twitch Enhanced Viewer | JeetBot,” that forwards each user’s live Twitch OAuth session token to proxy servers operated by a Russian commercial bot service. The extension ships on both the Chrome Web Store (extension ID pnhhdhhcadcjfckjhpmjneldiegbojfb, 30,000 users) and Firefox Add-ons (twitchenhancedviewer@example.com, 552 users). Both listings are live at time of writing.
Popular Twitch ad blocker caught sending live account credentials to Russian proxies
Threat Research Team identified a cross-store browser extension, “Twitch Enhanced Viewer | JeetBot,” that forwards each user’s live Twitch OAuth session token to proxy servers operated by a Russian commercial bot service. The extension ships on both the Chrome Web Store (extension ID pnhhdhhcadcjfckjhpmjneldiegbojfb, 30,000 users) and Firefox Add-ons (twitchenhancedviewer@example.com, 552 users). Both listings are live at time of writing.
Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.Kush Pandya (Socket)
like this
deliriousdreams likes this.
Carlos Solís
in reply to alapakala • •Privacy reshared this.
alapakala
in reply to Carlos Solís • • •I swear all Manifest V3 & XPI are source readable.
Though Russian is a req..
Carlos Solís
in reply to alapakala • •Privacy reshared this.
alapakala
in reply to Carlos Solís • • •Carlos Solís likes this.
Linearity
in reply to alapakala • • •I’ve made a v2 extension for Firefox, you CAN have obfuscated code in an extension by compiling it. HOWEVER, Mozilla requires you to submit the source code for any compiled/obfuscated code. Google has no reason not to catch it.
Compressed XPI packages can still be read afaik, they’re just JavaScript, CSS and HTML files at the end of the day.
like this
Carlos Solís likes this.
alapakala
in reply to Linearity • • •Apparently lying on threadiverse is also a requirement, seeing as you have no problems with it. JeetBot made no attempt to obfuscate their credential requiring addon, for other API means than to do both.
This was “Я верю в это.” No afterthought, no review.
Evolution of morality - Wikipedia
Contributors to Wikimedia projects (Wikimedia Foundation, Inc.)Privacy reshared this.
Linearity
in reply to alapakala • • •Privacy reshared this.
alapakala
in reply to Linearity • • •Linearity
in reply to alapakala • • •I did not mention Google not having this measure (nor was I aware of it), I only stated what I knew. And this only proves my argument further anyway: Google has no reason not to catch it. (“it” being the malicious extension)
There were no lies in my comment but you jumped the gun, accused me of lying and were rude about it too.
Calling out misinformation is good, just please be politer.
alapakala
in reply to Linearity • • •GasMaskedLunatic
in reply to alapakala • • •like this
Carlos Solís y Triumph like this.
sovietknuckles [she/her]
in reply to alapakala • • •I wouldn't install an add-on that hasn't been vetted with, at the very least, more positive reviews.
I use Alternate Player for Twitch.tv on Firefox, which also has a Russian developer, but it has 4.2 stars and 895 reviews
Also,
like this
warm y Carlos Solís like this.