ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Malware Removal
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

Browser Extensions Are a Supply Chain Risk: Lessons from the Twitch OAuth Leak

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. Browser Extensions Are a Supply Chain Risk: L...
  • All articles
  • Categories
  • Tags
  • Statuses

Browser Extensions Are a Supply Chain Risk: Lessons from the Twitch OAuth Leak

When a browser add-on becomes the weakest linkBrowser extensions are convenient, but they also run with extensive privileges inside the browser. A rec...

When a browser add-on becomes the weakest link

Browser extensions are convenient, but they also run with extensive privileges inside the browser. A recent incident involving a Twitch viewing extension, Twitch Enhanced Viewer | JeetBot, shows how quickly that convenience can turn into a supply chain risk. The extension, available in both the Chrome Web Store and Mozilla Add-ons, was found to forward OAuth session tokens to proxy servers controlled by its operator. According to reports, credentials from around 31,000 users were exposed. The case is a reminder that even official extension catalogues do not guarantee safety.

A key representing an OAuth token escaping from a browser extension into a proxy server

Why OAuth tokens are not just harmless identifiers

OAuth tokens are bearer credentials: whoever holds them can act as the authenticated user. In the case of Twitch, that means reading and sending whispers, posting in chat, or changing account settings without knowing the password or passing two-factor authentication. The most concerning behaviour appeared in the v85.x branch, where the extension added the token as an &auth= query parameter during network-level redirects to operator-controlled proxy servers. Because the token travelled inside a URL, it could be stored in plain text in proxy logs, increasing the risk if those logs were accessed improperly or leaked. The forwarding applied to almost any channel a user opened, with a default exception list of ten channels. From version 85.8.4, the extension even allowed restrictions to be adjusted through a parameter, but that did not address the underlying exfiltration. Earlier v4.x versions had already sent tokens via POST to a set-token endpoint, with backup endpoints on deno.dev and deno.net.

What to do if you or your team used the extension

The fix is available in Firefox from version 85.8.7, which stops sending the token by changing how playlists are obtained. A Chrome patch was reportedly in preparation. However, updating or disabling the extension only stops the leak from that point onwards; it does not invalidate tokens that have already left. If you used the extension, take these steps:

  • Uninstall or disable Twitch Enhanced Viewer | JeetBot immediately.
  • On Firefox, update to at least version 85.8.7.
  • Close all active Twitch sessions from the account settings and sign in again to force session rotation.
  • Review recent activity, private messages, and chat actions for unauthorised use.

Extension hygiene for organisations

For managed teams and companies, this incident fits a familiar pattern: extensions that can intercept or redirect traffic from authenticated services. Basic hygiene includes inventorying installed extensions, blocking affected identifiers by policy (pnhhdhhcadcjfckjhpmjneldiegbojfb in Chrome and twitchenhancedviewer@example.com in Firefox), and prioritising allowlists in corporate browsers. Convenience should not have unlimited access to a session. In Spain, where GDPR and local data protection rules apply, a token leak can also trigger notification obligations if personal data is compromised.

Beyond the browser: protecting your own infrastructure

The same principle applies to servers. A single compromised credential can give an attacker a foothold, and many organisations run several machines with inconsistent protection. That is where a centralised approach helps. Abuse Shield from ALMC centralises server protection: it automatically blocks malicious IPs, manages fail2ban across multiple machines, and shares an IP reputation feed between all your servers. Instead of configuring each server separately, you get a single view and a coordinated response. For system administrators, hosting companies, and SMEs in Barcelona, Lleida, Tarragona, or Girona with their own servers, this reduces the window of opportunity for attackers and simplifies compliance.

Conclusion

Supply chain attacks are not limited to npm packages or third-party libraries; browser extensions are part of the same attack surface. The Twitch OAuth leak shows that token theft can happen quietly and at scale. Review your extensions, rotate sessions after any suspected exposure, and apply the same rigour to your servers. Centralised tools like Abuse Shield can help you keep malicious IPs at bay and maintain a consistent security posture across your infrastructure.

Related

  • How to Harden Your Servers with Fail2ban and IP Reputation Feeds
  • Fail2ban: Your First Line of Defense Against Unauthorized Server Access
  • Critical libssh2 flaw: urgent patch for SSH servers
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Virtualization & Containers (Docker, Kubernetes)
Compliance Consulting (GDPR, ENS, ISO 27001)
Monitoring & Incident Response (SIEM)
API Integrations & Microservices
Full Stack Web Development Laravel, Vue.js
Relacionados
  • OAuth Token Leak: Supply Chain Lessons for Server Security
    Cybersecurity · 3 hours ago
  • Browser Extension Leaks OAuth Tokens: Lessons for Server Security
    Cybersecurity · 3 hours ago
  • Artifactory Under Siege: Lessons for Server Security
    Cybersecurity · 3 days ago
  • Supply Chain Phishing: When Your Email Provider Becomes the Attack Vector
    Cybersecurity · 4 days ago
  • How to Harden Your Servers with Fail2ban and IP Reputation Feeds
    Cybersecurity · 6 days ago
  • Critical libssh2 flaw: urgent patch for SSH servers
    Cybersecurity · 6 days ago
Servidores MCP Destacados
  • Travel MCP Server
    Productivity
  • Atla
    Official 🌟 Oficial
  • Maya MCP
    Development
  • Upbit MCP Server
    Communication
  • Kakuyomu MCP Server
    Web Scraping
  • Advanced Unity MCP Integration
    Development
  • Airtable User MCP
    Database
  • HubSpot MCP Server by CData
    Cloud Service
  • Cursor Chat History MCP
    Development
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-15
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar