A malicious browser extension targeting Twitch users is reported to have exfiltrated OAuth tokens from about 31,000 accounts. Security researcher Socket says the extension forwards tokens to a bot service hosted through Russian infrastructure, enabling unauthorized access tied to users’ authenticated sessions.

Both outlets describe the same core incident: a supply-chain style compromise through a browser extension that captures sensitive authentication data. TechRadar adds that the extension is later updated to remove the OAuth-stealing behavior, indicating the activity may have been modified or curtailed after detection. Infosecurity Magazine focuses on Socket’s discovery and the mechanism of token forwarding to the external service.

While details about the full scope of impacted accounts beyond the 31,000 figure are not established in the provided reports, the agreed-upon takeaway is that OAuth credentials were exposed via the extension’s operation and that the extension behavior changes after the discovery.