cross-posted from: https://piefed.world/c/tech/p/1400813/popular-twitch-ad-blocker-caught-sending-live-account-credentials-to-russian-proxies

Threat Research Team identified a cross-store browser extension, “Twitch Enhanced Viewer | JeetBot,” that forwards each user’s live Twitch OAuth session token to proxy servers operated by a Russian commercial bot service. The extension ships on both the Chrome Web Store (extension ID pnhhdhhcadcjfckjhpmjneldiegbojfb, 30,000 users) and Firefox Add-ons (twitchenhancedviewer@example.com, 552 users). Both listings are live at time of writing.

  • GasMaskedLunatic@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    32
    arrow-down
    1
    ·
    4 days ago

    A Google vetted source allowing code that compromises the end user? That’s simply not possible. The developer had to provide an ID to publish the code. It MUST be safe! /s