Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service
Blog post from Socket
Security researchers reported that “Twitch Enhanced Viewer | JeetBot,” a Chrome and Firefox extension installed by roughly 31,000 users, captures live Twitch OAuth session tokens and forwards them through proxy infrastructure linked to the Russian-language JeetBot bot service. Marketed as a tool for ad blocking, stream quality controls, region access, and automatic channel-point collection, the extension redirects video-playlist traffic through operator-controlled servers and appends users’ account-level tokens as URL parameters, potentially exposing them in server logs. Earlier versions reportedly sent captured tokens directly to dedicated collection endpoints, while current versions omit tokens only for a hardcoded list of ten Russian streamer channels. The researchers attribute the associated infrastructure to JeetBot and identify discrepancies between the extension’s token handling and its store privacy disclosures, which state that user data is not collected or processed. Because the credentials could allow account actions such as chat activity, whispers, and channel-point spending without a password or second factor, users are advised to remove the extension, revoke existing Twitch sessions, and reauthenticate, while organizations are encouraged to block the identified infrastructure and assess extensions with access to authenticated web services.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.