{"id":2822,"date":"2026-09-14T09:12:22","date_gmt":"2026-09-14T09:12:22","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2822"},"modified":"2026-09-14T09:12:22","modified_gmt":"2026-09-14T09:12:22","slug":"malicious-twitch-browser-extension-leaks-oauth-tokens-from-nearly-31000-users","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2822","title":{"rendered":"Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 14, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Browser Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEguNgykDjufnR6xGrMUSq67eZ5sCFxbYjf8J6pEXekhUnt-zCt2xaJ4jzj6I0wPMYjps9z2ufKJ-JSJ8ZqhGe4BcbtNWfRETdaB6QgIRVLw0CtnsM5q2qCpyI3kL7oBXmNixcTTcumZJHFgCKaoLY8kRIBDbPHslMmmzzb25TlESGooJuaxtXEL5qrUzkop\/s1700-nu-rw-lo-l85-e365\/twitch.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.<\/p>\n<p>The extension, named \u00abTwitch Enhanced Viewer | JeetBot,\u00bb lists HISHIMIRO\/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store &#8211;<\/p>\n<p>Both extensions are still available for download as of writing. The extension listing description states: \u00abJeetBot is a modern tool for streamers and viewers who appreciate quality, convenience, and control,\u00bb adding it \u00abexpands Twitch capabilities: 1080p stream for regions with constraints.\u00bb<\/p>\n<p>\u00abCurrent builds (v85.x) forward the token inline as an &amp;auth= query parameter on a network-layer redirect to the operator&#8217;s proxy,\u00bb Socket security researcher Kush Pandya <a href=\"https:\/\/socket.dev\/blog\/malicious-twitch-browser-extension\" target=\"_blank\">said<\/a>. \u00abThe token is forwarded for every channel the user watches, except a hardcoded allowlist of ten Russian streamer channels, whose sessions are exempted from forwarding.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe operator is a commercial Twitch, Kick, and VK-Live bot SaaS that has broad Twitch host permissions and relays live authenticated sessions through its own infrastructure.\u00bb<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>While the extension claims to offer an ad-free experience and serve region-unlocked content, it does so by routing Twitch&#8217;s video-playlist requests to \u00abusher.ttvnw[.]net\u00bb through operator-controlled proxy servers along with the user&#8217;s OAuth token as an \u00ab&amp;auth=\u00bb query parameter.<\/p>\n<p>Specifically, the add-on embeds code to recover the Twitch OAuth token and send it to the proxy. The token can enable access to a user&#8217;s chat, <a href=\"https:\/\/help.twitch.tv\/s\/article\/how-to-use-whispers?language=en_US\" target=\"_blank\">whispers<\/a> (i.e., private messages), and account settings.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhHSpVwNVIShcGzSiR5NffTEvF4sCDei3eZjfIG_qOfNpKVr7I3JaIWdpXhwnMsRZCOscYF6o7CeX3uVcz-WvZjhj420gUQgTHNq5Z7gxap0EWhABE6l_mDX9eupcc5p1KsLTdmE-fXIWEhRBG8fLRFS-pVbNXS2w3RhIt-2_O_gmZfGKzCmmsEZmJkNWid\/s1700-nu-rw-lo-l85-e365\/fire.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhHSpVwNVIShcGzSiR5NffTEvF4sCDei3eZjfIG_qOfNpKVr7I3JaIWdpXhwnMsRZCOscYF6o7CeX3uVcz-WvZjhj420gUQgTHNq5Z7gxap0EWhABE6l_mDX9eupcc5p1KsLTdmE-fXIWEhRBG8fLRFS-pVbNXS2w3RhIt-2_O_gmZfGKzCmmsEZmJkNWid\/s1700-nu-rw-lo-l85-e365\/fire.jpg\" alt=\"\" border=\"0\" data-original-height=\"468\" data-original-width=\"1000\"\/><\/a><\/div>\n<p>Given that the token is placed in the URL query string, it gets written in cleartext into the proxy server&#8217;s request logs. The token redirection mechanism, however, is excluded for a hard-coded list of 10 Twitch channels, most of them being Russian-language streamers with thousands of followers &#8211;<\/p>\n<ul>\n<li>pch3lk1n (580K followers)<\/li>\n<li>fasoollka (361K followers)<\/li>\n<li>flamie (132K followers)<\/li>\n<li>dosia (29 followers)<\/li>\n<li>fander (2 followers)<\/li>\n<li>almazer (4 followers)<\/li>\n<li>forzorezor (177K followers)<\/li>\n<li>akyuliych (1.1M followers)<\/li>\n<li>lagoda1337 (225K followers)<\/li>\n<li>lagoda (77.3K followers)<\/li>\n<\/ul>\n<p>\u00abFor every channel outside this list, the user\u2019s live token is forwarded to the proxy,\u00bb Pandya explained. \u00abEarlier v4.x builds (for example version 4.8, January 2026) went further, POSTing the token to a dedicated set-token endpoint on the operator host, with backups on deno.dev and deno.net.\u00bb<\/p>\n<p>JeetBot advertises itself as a \u00abpowerful bot for Twitch, Kick and VK Live with message speech synthesis, automatic translation, and many other features to enhance interaction with viewers.\u00bb It claims to have over 26,000 active streamers and 1 billion processed messages. The site&#8217;s footer identifies the operator to a Cyprus-based developer named Aleksandr Popov. On their LinkedIn profile, the developer claims JeetBot to be their pet project. <\/p>\n<p>However, it appears that the developer has already taken steps to address the problem. An alert issued on the <a href=\"https:\/\/docs.jeetbot.cc\/en\/base-stuff\/extension\/\" target=\"_blank\">JeetBot documentation page<\/a> now states that version 85.8.7 of the Firefox add-on addresses the problem and that an equivalent Chrome version is currently under review &#8211;<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/event-security-need\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJkE4t8oCql1wmWVt687J1yD7WnYRqvIpcsUwFSVUO-0HpxZWMCxLmeYwBlz38-C0KD-R6f9Pg0swgPTQuBsNXck_Kl3iKWNSQtyMcDNUSZGhiBd_XFu6U1SQi5LhuW-FHg00iT3CbRCUgMoCwhZevwxp8-9gwM2wZVVtGVO8Z2NbZ5EjVmI2dH4adnSAk\/s728-nu-rw-lo-l85-e365\/Shai-Hulud-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p><em>In the previous implementation, the extension sent the user&#8217;s Twitch OAuth token to our proxy servers to retrieve stream playlists. An OAuth token is a credential and must be protected.<\/em><\/p>\n<p><em>Version 85.8.7 changes how playlists are retrieved: the user&#8217;s OAuth token is no longer sent to our proxies.<\/em><\/p>\n<p><em>Check your installed extension version and update to 85.8.7 or later. Older installations using the previous mechanism continue to send the token until updated.<\/em><\/p>\n<p>The documentation also urges users to temporarily disable the extension to halt further transmission of the token if the extension is not available. However, the developer warned that disabling or updating the extension does not revoke previously transmitted tokens.<\/p>\n<p>The Hacker News has contacted both Socket and the developer for further comment and we will update the story if we hear back.<\/p>\n<p>\u00abApproximately 31,000 users across Chrome and Firefox route their live Twitch OAuth session tokens through operator-controlled proxy infrastructure,\u00bb Socket said.<\/p>\n<p>\u00abA Twitch OAuth session token is a bearer credential: whoever holds it can act on the account without the password or a second factor, including reading and sending whispers, posting in chat, and spending channel points. The exposure is undisclosed in both store listings.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 14, 2026Malware \/ Browser Security A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2823,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[265,520,843,33,381,146,3397,826],"class_list":["post-2822","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-browser","tag-extension","tag-leaks","tag-malicious","tag-oauth","tag-tokens","tag-twitch","tag-users"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2822","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2822"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2822\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2823"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2822"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2822"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2822"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}