← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Malicious Twitch Browser Extension Leaks OAuth Tokens from Nearly 31,000 Users

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Extension "Twitch Enhanced Viewer | JeetBot" leaks OAuth tokens.
  • Nearly 31,000 users affected across Chrome and Firefox.
  • Tokens sent to Russian bot service proxy servers.
  • Tokens provide access to chat, whispers, and account settings.

Malicious Extension Identified

A browser extension named "Twitch Enhanced Viewer | JeetBot" has been identified as malicious, leaking OAuth tokens from Twitch users. The extension, developed by HISHIMIRO/jeetbot.cc, is available on both the Google Chrome Web Store and Mozilla Firefox Add-Ons store. It claims to offer features like 1080p streaming for regions with constraints and an ad-free experience.

Scope of the Leak

The malicious extension has affected approximately 31,000 users. The Chrome version, published on June 26, 2025, accounts for 30,000 users, while the Firefox version, published on July 7, 2025, has 604 users. Both versions remain available for download as of the reporting time.

Mechanism of Token Exposure

The extension forwards users' OAuth tokens as an '&auth=' query parameter in network-layer redirects to operator-controlled proxy servers. This occurs for every channel a user watches, except for a hardcoded allowlist of ten Russian streamer channels. The tokens are written in cleartext into the proxy server's request logs, making them vulnerable. These tokens can grant access to a user's chat, private messages (whispers), and account settings.

Operator and Impact

The operator of the proxy servers is a commercial Twitch, Kick, and VK-Live bot SaaS. This service has broad Twitch host permissions and relays live authenticated sessions through its own infrastructure. The exclusion of specific Russian channels from token forwarding suggests a targeted or selective data exfiltration strategy.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Sep 13

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A malicious Twitch browser extension, "Twitch Enhanced Viewer | JeetBot," has been found leaking OAuth tokens from approximately 31,000 users to proxy servers operated by a Russian commercial bot service. These tokens, which grant access to user chat, whispers, and account settings, are exposed in cleartext via URL query strings when users watch channels not on a hardcoded allowlist.