A malicious Twitch browser extension has leaked the login tokens of nearly 31,000 users. Security researchers found it sent OAuth tokens to external proxy servers. Notably, those servers belong to a Russian commercial bot service. The finding highlights ongoing risks from seemingly harmless browser add-ons.
The extension is named “Twitch Enhanced Viewer | JeetBot.” It lists a developer identified as HISHIMIRO on both major stores. On the Chrome Web Store, it reached roughly 30,000 users. Meanwhile, a smaller Firefox version served about 604 more.
The extension marketed itself around appealing viewer features. Specifically, it promised an ad-free experience and region-unlocked content. It claimed to deliver 1080p streams for restricted regions too. However, delivering these features hid a serious security flaw.
To unlock content, it rerouted Twitch’s video requests through proxies. Crucially, it attached the user’s OAuth token to those requests. According to Socket researcher Kush Pandya, the token traveled as a query parameter. Consequently, it appeared in cleartext within the proxy’s request logs.
The stolen token grants dangerous access to a victim’s account. Essentially, it acts as a bearer credential without needing passwords. Therefore, an attacker could read and send private whispers freely. They could also post in chat and spend channel points.
The scheme included one especially telling detail. The token forwarding skipped a hardcoded list of ten channels. Most of these belonged to Russian-language streamers with large followings. This exemption strongly suggests a deliberate, targeted operation.
The bot service behind it operates commercially across several platforms. It claims over 26,000 active streamers and a billion processed messages. Notably, its footer links to a Cyprus-based developer. On LinkedIn, that developer called JeetBot a personal pet project.
However, the developer has begun addressing the problem directly. A documentation alert says version 85.8.7 fixes the Firefox issue. The token is reportedly no longer sent to their proxies. A matching Chrome update remains under review currently.
Crucially, users must take action beyond just updating. The developer warned that previously transmitted tokens are not revoked. Therefore, affected users should update, then reauthorize their Twitch sessions. For Pakistani streamers and viewers, checking installed extensions remains wise.
