Summary
A malicious browser extension for Twitch, named "Twitch Enhanced Viewer | JeeBot," has been found harvesting OAuth tokens from approximately 31,000 users and sending them to a Russian-owned server. Security researchers at Socket discovered that the extension deliberately exempted 10 Russian streamer channels from this data collection, suggesting intentional malicious activity despite the developer issuing fixes.