CYBER DELTA FORCESearch

Twitch extension with 30K installs exposes users’ OAuth tokens

A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users’ Twitch OAuth session tokens to a commercial bot service.

CDF News DeskBleepingComputer15 Sept 2026, 12:33 am
Image courtesy of The Hacker News. Original report
CDF REPORT

A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users’ Twitch OAuth session tokens to a commercial bot service. However, an analysis from application security company Socket shows that the extension captures the authorization header used by the Twitch web client, extracts the user OAuth token, and sends the credentials through proxy servers. The servers are operated by JeetBot, a commercial Russian-language streaming and chatbot service that offers tools for Twitch, Kick, and VK Live. In current versions of the extension, the token is appended directly to redirected proxy requests as an auth= URL parameter, ending up in the proxy server’s request logs, where the software vendor can easily retrieve it.

Socket highlights that earlier versions of the extension included more explicit credential-theft mechanisms.

Socket highlights that earlier versions of the extension included more explicit credential-theft mechanisms.

What changed

This is necessary for the stream to run in 1080/1440p.” [machine translated] The data privacy disclosure for the Chrome variant of Twitch Enhanced Viewer | JeetBot says that its developer “disclosed that it will not collect or use your data.” The declaration covers selling user data to third parties except for approved cases, transferring it for reasons outside the product’s “core functionality,” or “to determine creditworthiness or for lending purposes.” At the time of publishing, the extension was still present in both the Chrome Web Store and the Firefox Add-Ons store.

Who is affected

In the description of the product in the Firefox Add-ons store, the developer provided a disclaimer about the previously used mechanism, saying: “Previous versions of the extension transmit your OAuth-twitch token to our server.

Socket researchers believe the extension represents a security risk and recommend that users remove it from their browsers, disconnect all sessions in Twitch, and then re-authenticate, to invalidate any token that may have been forwarded.

Developers are advised to avoid routing requests with authentication headers or tokens through third-party servers.

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.

The technical picture

Socket highlights that earlier versions of the extension included more explicit credential-theft mechanisms.

What remains unknown

The available reporting does not establish whether the issue is being actively exploited in the wild.

The available reporting does not establish who is behind the activity, if an attacker is involved.

MORE IN CLOUD & IDENTITY

More cybersecurity reporting

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev ServersThe Hacker News · 15 Sept 2026, 4:42 pmChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGEThe Hacker News · 15 Sept 2026, 11:01 amUnmasking Cloud Identities: From Behavioral Clustering to Automated DetectionPalo Alto Unit 42 · 14 Sept 2026, 3:30 pmCISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVThe Hacker News · 12 Sept 2026, 9:24 pm