A browser extension named "Twitch Enhanced Viewer | JeetBot" has been identified as malicious, leaking OAuth tokens from Twitch users. The extension, developed by HISHIMIRO/jeetbot.cc, is available on both the Google Chrome Web Store and Mozilla Firefox Add-Ons store. It claims to offer features like 1080p streaming for regions with constraints and an ad-free experience.
The malicious extension has affected approximately 31,000 users. The Chrome version, published on June 26, 2025, accounts for 30,000 users, while the Firefox version, published on July 7, 2025, has 604 users. Both versions remain available for download as of the reporting time.
The extension forwards users' OAuth tokens as an '&auth=' query parameter in network-layer redirects to operator-controlled proxy servers. This occurs for every channel a user watches, except for a hardcoded allowlist of ten Russian streamer channels. The tokens are written in cleartext into the proxy server's request logs, making them vulnerable. These tokens can grant access to a user's chat, private messages (whispers), and account settings.
The operator of the proxy servers is a commercial Twitch, Kick, and VK-Live bot SaaS. This service has broad Twitch host permissions and relays live authenticated sessions through its own infrastructure. The exclusion of specific Russian channels from token forwarding suggests a targeted or selective data exfiltration strategy.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A malicious Twitch browser extension, "Twitch Enhanced Viewer | JeetBot," has been found leaking OAuth tokens from approximately 31,000 users to proxy servers operated by a Russian commercial bot service. These tokens, which grant access to user chat, whispers, and account settings, are exposed in cleartext via URL query strings when users watch channels not on a hardcoded allowlist.