Malicious Twitch Browser Extension Leaks OAuth Tokens for Nearly 31,000 Users
A malicious browser extension, "Twitch Enhanced Viewer | JeetBot," has exposed OAuth tokens for nearly 31,000 Twitch users by forwarding them to proxy servers operated by a Russian commercial bot service. The extension, developed by HISHIMIRO/jeetbot.cc and available on both the Google Chrome Web Store (30,000 users, published June 26, 2025) and Mozilla Firefox Add-Ons (604 users, published July 7, 2025), remains accessible as of this report.
The extension, marketed as a tool to enhance streaming quality including 1080p streams in restricted regions secretly harvests Twitch OAuth tokens by embedding them in URL query parameters (&auth=) during redirects to operator-controlled proxies. According to Socket security researcher Kush Pandya, the tokens are transmitted for every channel a user watches, except for a hardcoded allowlist of 10 Russian-language Twitch channels, including high-profile streamers like pch3lk1n (580K followers) and akyuliych (1.1M followers).
The leaked tokens grant full access to users' Twitch accounts, including chat, private messages (whispers), and account settings, without requiring passwords or two-factor authentication. Since the tokens are transmitted in plaintext via URL parameters, they are logged by the proxy servers, creating a persistent security risk. Earlier versions of the extension (e.g., v4.8, January 2026) went further, sending tokens via POST requests to dedicated endpoints.
JeetBot, the service behind the extension, is a commercial bot platform for Twitch, Kick, and VK Live, claiming over 26,000 active streamers and 1 billion processed messages. The operator, identified as Aleksandr Popov (a Cyprus-based developer), describes the project as a "pet project" on LinkedIn. Despite the breach, JeetBot has taken steps to mitigate the issue, releasing Firefox version 85.8.7 to remove token transmission and submitting an equivalent Chrome update for review. However, users who do not update remain exposed, and previously leaked tokens remain valid unless manually revoked.
The incident highlights the risks of third-party browser extensions, particularly those handling sensitive authentication tokens. With 31,000 users affected, the exposure underscores the potential for account hijacking, unauthorized chat access, and other malicious activities all without the victims' knowledge. Neither the Chrome nor Firefox store listings disclosed the token-forwarding behavior.
Source: https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html
Twitch cybersecurity rating report: https://www.rankiteo.com/company/twitch-tv
Mozilla cybersecurity rating report: https://www.rankiteo.com/company/mozilla-corporation
"id": "TWIMOZ1789381551",
"linkid": "twitch-tv, mozilla-corporation",
"type": "Vulnerability",
"date": "6/2025",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'customers_affected': '31,000',
'industry': 'Live Streaming',
'location': 'Global',
'name': 'Twitch Users',
'size': '31,000 users',
'type': 'Individuals'},
{'customers_affected': '31,000',
'industry': 'Live Streaming',
'location': 'Global',
'name': 'Twitch',
'size': 'Large',
'type': 'Company'}],
'attack_vector': 'Malicious Browser Extension',
'customer_advisories': 'Users should revoke OAuth tokens and update/remove '
'the extension.',
'data_breach': {'data_encryption': 'No (plaintext URL parameters)',
'data_exfiltration': 'Yes (via proxy servers)',
'number_of_records_exposed': '31,000',
'personally_identifiable_information': 'Account credentials '
'(indirectly)',
'sensitivity_of_data': 'High (full account access)',
'type_of_data_compromised': 'OAuth Tokens'},
'description': "A malicious browser extension, 'Twitch Enhanced Viewer | "
"JeetBot,' has exposed OAuth tokens for nearly 31,000 Twitch "
'users by forwarding them to proxy servers operated by a '
'Russian commercial bot service. The extension, developed by '
'HISHIMIRO/jeetbot.cc, remains accessible on the Google Chrome '
'Web Store and Mozilla Firefox Add-Ons. The leaked tokens '
"grant full access to users' Twitch accounts, including chat, "
'private messages, and account settings, without requiring '
'passwords or two-factor authentication.',
'impact': {'brand_reputation_impact': 'High (Twitch and affected streamers)',
'data_compromised': 'OAuth Tokens (31,000 users)',
'identity_theft_risk': 'High (account hijacking risk)',
'operational_impact': 'Unauthorized account access, chat '
'manipulation, private message exposure',
'systems_affected': 'Twitch User Accounts'},
'initial_access_broker': {'backdoors_established': 'Proxy servers logging '
'OAuth tokens',
'entry_point': 'Malicious Browser Extension',
'high_value_targets': 'Twitch streamers (e.g., '
'pch3lk1n, akyuliych)'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Risks of third-party browser extensions handling '
'sensitive authentication tokens, need for transparency in '
'extension permissions and data handling.',
'motivation': 'Commercial Bot Service Operations',
'post_incident_analysis': {'corrective_actions': 'Extension updates to remove '
'token transmission, manual '
'token revocation for '
'affected users, stricter '
'platform review policies '
'for extensions.',
'root_causes': 'Lack of transparency in extension '
'functionality, insecure OAuth '
'token handling (plaintext URL '
'parameters), insufficient review '
'processes for browser extensions.'},
'recommendations': 'Users should revoke OAuth tokens, update or remove the '
'malicious extension, and monitor account activity. '
'Platforms should enforce stricter review processes for '
'extensions handling authentication tokens.',
'references': [{'source': 'Socket Security (Kush Pandya)'},
{'source': 'Google Chrome Web Store'},
{'source': 'Mozilla Firefox Add-Ons'}],
'response': {'containment_measures': 'Extension updates to remove token '
'transmission (Firefox v85.8.7, Chrome '
'update submitted for review)',
'remediation_measures': 'Manual OAuth token revocation for '
'affected users',
'third_party_assistance': 'Socket Security (Researcher: Kush '
'Pandya)'},
'threat_actor': 'JeetBot (Aleksandr Popov)',
'title': 'Malicious Twitch Browser Extension Leaks OAuth Tokens for Nearly '
'31,000 Users',
'type': 'Data Breach',
'vulnerability_exploited': 'OAuth Token Leak via URL Parameters'}