Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
A malicious Twitch browser extension, "Twitch Enhanced Viewer | JeetBot," has been leaking OAuth tokens from nearly 31,000 users to a Russian commercial bot service. The extension, developed by a Cypriot developer, routes Twitch video requests through proxy servers, exposing user data like chat messages and account settings. While the developer has released an update to mitigate the issue, users are advised to disable the extension until they can update to address the ongoing risk of token exposure.
A malicious cross-store Twitch browser extension, "Twitch Enhanced Viewer | JeetBot," has been leaking OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, developed by a Cypriot developer named Aleksandr Popov, and listed on both the Google Chrome Web Store and Mozilla Firefox Add-Ons store, routes Twitch video requests through these proxy servers.
Specifically, the add-on embeds code to recover the Twitch OAuth token and send it to the proxy. The token can enable access to a user's chat, whispers (i.e., private messages), and account settings. The developer claims the extension offers features like ad-free viewing and region-unlocked content, boasting over 26,000 active streamers and 1 billion processed messages.
Version 85.8.7 of the Firefox add-on addresses the problem by no longer sending the user’s OAuth token to the proxy servers. However, older installations using the previous mechanism continue to send the token until updated. The documentation also urges users to temporarily disable the extension to halt further transmission of the token if the extension is not available.
The operator, identified as a commercial Twitch, Kick, and VK-Live bot SaaS, has broad Twitch host permissions and relays live authenticated sessions through its own infrastructure. The developer’s LinkedIn profile indicates this is a personal project.
Socket security researcher Kush Pandya discovered the vulnerability and highlighted that approximately 31,000 users across Chrome and Firefox route their live Twitch OAuth session tokens through operator-controlled proxy infrastructure. A Twitch OAuth session token is a bearer credential: whoever holds it can act on the account without the password or a second factor, including reading and sending whispers, posting in chat, and spending channel points. The exposure is undisclosed in both store listings.
As of writing, both extensions remain available for download. The Hacker News has contacted Socket and the developer for further comment and will update the story if we hear back.
