BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
DarkDotWeb · Sep 14, 2026 · 3 min read · Original story

Malicious Twitch Extension Exposes 31,000 OAuth Tokens

Malicious Twitch Extension Exposes 31,000 OAuth Tokens

A Twitch browser extension sent OAuth tokens from nearly 31,000 users to proxy servers operated by the JeetBot service.

A Twitch browser extension with more than 30,000 users has been found sending users’ live OAuth session tokens to proxy servers operated by a Russian commercial bot service.

The extension, called “Twitch Enhanced Viewer | JeetBot,” is available for both Google Chrome and Mozilla Firefox. Security researchers at Socket found that the extension was forwarding account-level Twitch authentication tokens through infrastructure controlled by the operator.

According to Socket, around 30,000 Chrome users and several hundred Firefox users were affected.

The extension advertises features designed to improve the Twitch viewing experience, including ad blocking, access to higher-quality streams in restricted regions and other viewing features.

To provide some of these functions, the extension redirects Twitch video playlist requests through its own proxy infrastructure.

The problem is that the requests can also contain the user’s Twitch OAuth token.

Socket researcher Kush Pandya said current versions of the extension, in the 85.x series, append the token to the request as an “auth” parameter in the URL. This means the credential can also be recorded in proxy server logs.

Socket determined that the token is an account-scoped Twitch OAuth credential rather than a token limited to video playback.

That distinction is significant because possession of the credential could allow someone to interact with the affected Twitch account without knowing its password or bypassing its second-factor authentication.

Potential access includes Twitch chat, private whispers, account settings and channel points.

Socket found that the extension contained a hardcoded list of ten Twitch channels whose sessions were excluded from the token-forwarding mechanism.

Most of the exempted channels belong to Russian-speaking streamers.

For channels outside that list, Socket said the user’s live OAuth token was forwarded to the operator-controlled proxy.

The researchers also found that earlier versions of the extension used an even more direct method of sending tokens to the operator’s infrastructure.

For example, version 4.8 from January 2026 reportedly sent captured tokens to a dedicated “set-token” endpoint, with additional backup infrastructure hosted through Deno services.

JeetBot describes itself as a commercial bot service for Twitch, Kick and VK Live. Its website claims to provide tools including automated interaction, translation and other features for streamers.

The extension lists HISHIMIRO as its developer.

The Hacker News reported that the service’s website identifies Cyprus-based developer Aleksandr Popov as its operator. Popov’s LinkedIn profile describes JeetBot as a personal project.

Socket said the extension’s behavior conflicts with the disclosures associated with the add-on, including statements indicating that user data is not collected, stored or processed.

The developer appears to have taken steps to address the problem after the issue was identified.

A notice on the JeetBot documentation states that Firefox version 85.8.7 changes how Twitch playlists are retrieved so that the user’s OAuth token is no longer sent through the proxy.

The developer also said an equivalent Chrome update was under review.

However, simply updating or disabling the extension does not invalidate OAuth tokens that may already have been transmitted.

Users who installed the affected extension should therefore treat their Twitch sessions as potentially exposed and sign out of active sessions before signing back in.

The extension had more than 30,000 Chrome users when Socket’s research was published, along with several hundred Firefox installations.

The incident is another reminder that browser extensions can have access to highly sensitive authentication data even when their advertised purpose appears relatively harmless.

Source: The Hacker News

References in this story

  1. Twitch Enhanced Viewer | JeetBot – Get this Extension for 🦊 Firefox (en-US) addons.mozilla.org Download Twitch Enhanced Viewer | JeetBot for Firefox. Расширяет возможности Twitch: поток 1080p для регионов с ограничениями, интеграция с JeetBot
  2. Twitch www.twitch.tv Twitch is an interactive livestreaming service for content spanning gaming, entertainment, sports, music, and more.
  3. LinkedIn: Log In or Sign Up www.linkedin.com 1 billion members | Manage your professional identity. Build and engage with your professional network. Access knowledge, insights and opportunities.
  4. Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users thehackernews.com JeetBot's Twitch extension sent OAuth tokens from nearly 31,000 users to operator-controlled proxies; Firefox 85.8.7 stops the behavior.

Guides related to this story

← Back to all news