Malicious 'Twitch Enhanced Viewer | JeetBot' Extension Exposes OAuth Tokens of ~31,000 Chrome and Firefox Users
The cross-store browser extension 'Twitch Enhanced Viewer | JeetBot' forwarded live account-scoped OAuth session tokens of roughly 31,000 users (~30,000 Chrome, 552 Firefox) in cleartext to Russian JeetBot proxy infrastructure, enabling account access without…
Research by Socket found that the malicious cross-store extension 'Twitch Enhanced Viewer | JeetBot' rerouted Twitch video/playlist requests through operator-controlled JeetBot proxy servers, appending the victim's account-scoped OAuth bearer token in cleartext as a URL query parameter where it could be logged in proxy logs. Version 4.x builds, including version 4.8 from January 2026, also posted captured tokens to dedicated set-token endpoints on JeetBot infrastructure, with backups on two Deno services. Roughly 30,000 Chrome and 552 Firefox installs were exposed — about 31,000 total — with tokens forwarded for nearly every channel viewed. The exfiltration is tied to infrastructure of a Russian commercial bot service, and IoCs have been published. A stolen bearer token allows reading and sending whispers, posting in chat, accessing account settings, and spending channel points without the victim's password or 2FA. At publication, listings were still live on both the Chrome Web Store and Firefox Add-ons; affected users are advised to remove the extension and re-authenticate all sessions.
- Malicious extension: 'Twitch Enhanced Viewer | JeetBot', distributed on both Chrome Web Store and Firefox Add-ons
- Roughly 31,000 installs affected: about 30,000 Chrome and 552 Firefox users
- Extension routed Twitch video/playlist requests through operator-controlled JeetBot proxy servers, with the account-scoped OAuth bearer token appended in cleartext as a URL query parameter
- Tokens were forwarded for nearly every channel viewed and exposed in cleartext proxy logs
- Version 4.x builds, including 4.8 released January 2026, posted captured tokens to dedicated set-token endpoints on JeetBot infrastructure, with backups on two Deno services
- Stolen tokens enable chat posting, reading and sending whispers, account-settings access, and channel-point spending without the password or 2FA
- Exfiltration infrastructure is tied to a Russian commercial bot service; IoCs have been published
- Extension listings were still live on both stores at publication time
Coverage timelineoldest first · each row is one article
- · 1d agoMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News· 52
Malicious 'Twitch Enhanced Viewer | JeetBot' browser extension stole live OAuth session tokens from roughly 31,000 Chrome and Firefox users.
- · 1d agoMalicious Twitch Extension Exposes 31,000 Users' OAuth Tokens
Infosecurity Magazine· 50
Malicious Twitch extension 'Twitch Enhanced Viewer | JeetBot' forwarded live OAuth session tokens of roughly 31,000 users to Russian JeetBot proxy servers.