We’re Casterlabs, the free stream suite! Grab our desktop app today!

Latvia & The USA
⚡ Turbocharge your live streams with Caffeinated!⚡ ☕ That's right, your favorite software can now be brewed to give yourself a competitive edge and set your streams apart from your peers! ☕ 🥰 Your fans will LOVE the new you!🥰 drink-caffeinated.casterlabs…
6
3
20
4,296
Message was too long to bring to X directly, here's a screenshot (sorry!) Additional info in the replies:
6
100
392
47,538
Looks like the Fedora package for OBS already has a fix in place for the code execution exploit. However, you should still scrutinize your widgets to ensure that they aren’t vulnerable to XSS exploits as they can still act maliciously (do the pink test)
BTW, OBS in Fedora is not affected. Fedora has been shipping its OBS package with ~up to date CEF for a long time now. Either way, this is only a risk if you use an unsafe or buggy chat widget. It doesn't mean everyone can get hacked through chat.
3
476
Casterlabs retweeted
A malicious Twitch chat message can trigger code execution in OBS Studio. The attack targets OBS Studio and custom Twitch chat overlays (Browser Sources) that insert unsanitized chat directly into the page and can execute JS within the overlay. cyberinsider.com/malicious-t…
Community note
Chat alone can’t hack OBS. The proof of concept needed a custom overlay that rendered messages as unsafe HTML, plus a flaw in OBS 32.2.2’s built-in browser. It doesn’t show Streamlabs or StreamElements are vulnerable. OBS has merged a browser update for 33.0. blog.scrt.ch/2026/09/22/how… github.com/obsproject/obs…
63
425
1,621
299,802
Copy/pastable text to test your widgets: <span style="color: pink;">test</span> Note, this is not a foolproof test. When in doubt, disable everything and wait for an update to address this issue. Stay safe out there!
8
1,822
Caffeinated now supports Tier 2 and 3 sub gifs on Twitch!
3
5
24
671
More information about Twitch's sub gifs: help.twitch.tv/s/article/gif…
1
3
162
It's pronounced /ɡɪf/ btw.
4
76
We've updated our Privacy Policy. You can read it here: casterlabs.co/privacy-policy
3
1
9
1,310
Shortlist of changes: - We no longer use Microsoft Clarity in our products. - We have tightened our language surrounding business partners as we do not share personal information with them. - We now have a listed "Effective date" for future revisions to our privacy policy.
1
9
675
We have opted to mark these changes as effective immediately seeing as they strengthen your privacy as a user and reduce our ability to collect/use certain types of data.
6
447
Forgot to come up with an April fool’s tweet for this year. So instead, I will tell you an April Truth: I (@ItzLcyx) own and operate a live-streaming platform. Won’t tell ya which, won’t confirm it either. Happy AF, reply with the funniest ones y’all have seen so far :)
1
7
662
Hi @Cloudflare/@CloudflareHelp, any word on the 1016 errors in Workers when resolving domains that are fully controlled by Cloudflare? We do not see any active issue on the status page and want to make sure that this is known about. It has been happening off and on all week. TY!
2
1
9
1,027
follow-up: we got confirmation of the issue and have a temporary workaround for those affected while the CF engineers work on the issue :) status.casterlabs.co/inciden…
3
287
Ran a dig, looks like Cloudflare's DNS resolution is very broken at the moment.
2
1
4
353
Tagging @dok2001 for visibility :) These DNS records are grey-clouded, so no funky partial proxy stuff is going on. And Cloudflare controls both domains (and they are definitely valid, as of 2 years ago). Been having this issue intermittently for the past month or so.
1
4
262
six years :) some big updates are coming y'all's way. ETA 1-2 months depending on how many bugs pop up and how quickly i can squash them :)
7
1
25
1,179
Amazing day when the ~$89m company decides to start telling people to uninstall Casterlabs because it's somehow preventing <company's> alerts from working..? Also cool that they "recommend" people switch to <our direct competitor> who somehow don't have this "issue?" Sigh.
8
25
1,599
like, it's pretty obvious that two independent applications cannot "steal" events from eachother. if that were the case, they could just steal the events before we could. and fwiw, no streaming platform has the ability for one app to deny another app access to information.
1
7
849
Uninstall our competitor and things will magically work again! Oh wait it didn't fix it? Well use something else anyway!
8
737