Twitch: Malicious Twitch browser extension exposed user tokens

Twitch: Malicious Twitch browser extension exposed user tokens

Malicious Twitch Extension Exposed OAuth Tokens of 31,000 Users

A rogue browser extension, Twitch Enhanced Viewer | JeetBot, has been found harvesting live OAuth session tokens from approximately 31,000 Twitch users and transmitting them to proxy servers linked to a Russian commercial bot service. Discovered by security firm Socket, the extension available on the Chrome Web Store and Firefox Add-ons advertised features like ad blocking and region unlocking but covertly exfiltrated sensitive credentials.

The extension intercepted Twitch video-playlist requests, routing them through its own proxy servers while appending users' account-scoped OAuth tokens in cleartext as URL parameters. These tokens, unnecessary for the extension’s stated functions, granted unauthorized access to private messages, chat interactions, and channel point spending all without additional authentication.

Early versions of the extension, dating back to January 2026, directly posted stolen tokens to a JeetBot-controlled endpoint. Later iterations shifted to inline forwarding, though the extension’s privacy policy and data-safety disclosures failed to mention this behavior. Security researchers warn that browser extensions with host permissions and third-party proxy integrations pose a significant credential exposure risk. Users are advised to remove the extension, terminate active Twitch sessions, and re-authenticate to revoke compromised tokens.

Source: https://www.msspalert.com/brief/malicious-twitch-browser-extension-exposed-user-tokens

Twitch cybersecurity rating report: https://www.rankiteo.com/company/twitch-tv

"id": "TWI1789496800",
"linkid": "twitch-tv",
"type": "Breach",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '31,000 users',
                        'industry': 'Live Streaming / Social Media',
                        'location': 'Global',
                        'name': 'Twitch',
                        'size': 'Large',
                        'type': 'Company'}],
 'attack_vector': 'Malicious Browser Extension',
 'customer_advisories': 'Users advised to remove the extension, terminate '
                        'active Twitch sessions, and re-authenticate.',
 'data_breach': {'data_encryption': 'No (tokens sent in cleartext as URL '
                                    'parameters)',
                 'data_exfiltration': 'Yes (tokens transmitted to '
                                      'JeetBot-controlled proxy servers)',
                 'number_of_records_exposed': '31,000',
                 'personally_identifiable_information': 'Potentially (private '
                                                        'messages, chat '
                                                        'interactions)',
                 'sensitivity_of_data': 'High (grants access to user accounts '
                                        'without additional authentication)',
                 'type_of_data_compromised': 'OAuth session tokens'},
 'description': 'A rogue browser extension, *Twitch Enhanced Viewer | '
                'JeetBot*, has been found harvesting live OAuth session tokens '
                'from approximately 31,000 Twitch users and transmitting them '
                'to proxy servers linked to a Russian commercial bot service. '
                'The extension intercepted Twitch video-playlist requests, '
                'routing them through its own proxy servers while appending '
                "users' account-scoped OAuth tokens in cleartext as URL "
                'parameters. These tokens granted unauthorized access to '
                'private messages, chat interactions, and channel point '
                'spending without additional authentication.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage to '
                                       'Twitch',
            'data_compromised': 'OAuth session tokens',
            'identity_theft_risk': 'High (OAuth tokens could enable account '
                                   'takeover)',
            'operational_impact': 'Unauthorized access to private messages, '
                                  'chat interactions, and channel point '
                                  'spending',
            'systems_affected': 'Twitch user accounts'},
 'initial_access_broker': {'entry_point': 'Malicious browser extension '
                                          '(*Twitch Enhanced Viewer | '
                                          'JeetBot*)'},
 'lessons_learned': 'Browser extensions with host permissions and third-party '
                    'proxy integrations pose significant credential exposure '
                    'risks. Users should scrutinize extension permissions and '
                    'privacy disclosures.',
 'motivation': 'Credential harvesting for unauthorized access',
 'post_incident_analysis': {'corrective_actions': 'Enhanced scrutiny of '
                                                  'browser extensions, '
                                                  'improved OAuth token '
                                                  'security, and user '
                                                  'education on extension '
                                                  'risks',
                            'root_causes': 'Lack of transparency in extension '
                                           'privacy policy, excessive '
                                           'permissions, and proxy-based token '
                                           'interception'},
 'recommendations': 'Remove the malicious extension, terminate active Twitch '
                    'sessions, re-authenticate to revoke compromised tokens, '
                    'and monitor for unauthorized account activity.',
 'references': [{'source': 'Socket Security Firm'}],
 'response': {'communication_strategy': 'Public advisory to users',
              'containment_measures': 'Users advised to remove the extension '
                                      'and terminate active Twitch sessions',
              'remediation_measures': 'Re-authenticate to revoke compromised '
                                      'tokens',
              'third_party_assistance': 'Security firm Socket'},
 'threat_actor': 'Russian commercial bot service (JeetBot)',
 'title': 'Malicious Twitch Extension Exposed OAuth Tokens of 31,000 Users',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Exploitation of OAuth tokens via proxy '
                            'interception'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.