Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service

Blog post from Socket

Post Details
Company
Date Published
Author
Kush Pandya
Word Count
1,744
Company Posts That Month
35
Language
English
Hacker News Points
-
Post removed?
No
Summary

Security researchers reported that “Twitch Enhanced Viewer | JeetBot,” a Chrome and Firefox extension installed by roughly 31,000 users, captures live Twitch OAuth session tokens and forwards them through proxy infrastructure linked to the Russian-language JeetBot bot service. Marketed as a tool for ad blocking, stream quality controls, region access, and automatic channel-point collection, the extension redirects video-playlist traffic through operator-controlled servers and appends users’ account-level tokens as URL parameters, potentially exposing them in server logs. Earlier versions reportedly sent captured tokens directly to dedicated collection endpoints, while current versions omit tokens only for a hardcoded list of ten Russian streamer channels. The researchers attribute the associated infrastructure to JeetBot and identify discrepancies between the extension’s token handling and its store privacy disclosures, which state that user data is not collected or processed. Because the credentials could allow account actions such as chat activity, whispers, and channel-point spending without a password or second factor, users are advised to remove the extension, revoke existing Twitch sessions, and reauthenticate, while organizations are encouraged to block the identified infrastructure and assess extensions with access to authenticated web services.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.