Twitch extension with 30K installs exposes users’ OAuth tokens

2026-09-14T19:23:21Z•31f48158d2411eeb5d3fb6bebb92fa99f56690475277a339f7cb1a98bf408c4e
CVE-2026-51990CVE-2026-85102CVE-2026-85103active-exploitationawsazurebackdoorcloud-securitycredential-theftcritical-vulnerabilitiesdata-breachgitlabinformation-stealerjfrog-artifactorymalwaremicrosoft-365oauth-token-theftpatch-managementphishingsupply-chain-riskvitevpn-security

What happened

Security news feed covering active exploitation, data breaches, credential and OAuth theft, phishing, malware deployment, exposed development infrastructure, and software update issues. Notable threats include exploitation of critical Check Point VPN, GitLab, Tencent Sogou Input Method, and JFrog Artifactory vulnerabilities; campaigns targeting exposed Vite servers and Microsoft 365 accounts; malicious browser extensions exfiltrating Twitch OAuth tokens; and breaches affecting Revolut and Florida's DMV database.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
31f48158d2411eeb5d3fb6bebb92fa99f56690475277a339f7cb1a98bf408c4e
Enrichment time
2026-09-14T19:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Twitch extension with 30K installs exposes users’ OAuth tokens · Baitaphish