31,000 Twitch users hit by malicious browser extension OAuth tokens leaked via Russian proxy network
Date:
Mon, 14 Sep 2026 19:05:00 +0000
Description:
The extension has since been updated to remove the OAuth exfil.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Socket found Twitch extension JeeBot harvesting OAuth tokens via proxy servers Tokens excluded only for 10 Russian streamer channels, suggesting deliberate design Developer issued fixes, but users should revoke exposed tokens for safety A browser extension for Twitch was harvesting peoples OAuth tokens and sending them to a Russian-owned server. The move was deliberate, but whether or not it was malicious is not that easily determined.
Security researchers Socket recently found an extension for both Chrome and Firefox, called Twitch Enhanced Viewer | JeeBot. It has roughly 30,000 users on Chrome, and some 600 on Firefox. On the Chrome Web Store, it is advertised as a modern tool for streamers and viewers who value quality, convenience,
and control. Apparently, it makes streaming and viewing clearer, allows viewing content in 2K, hides banner ads and unwanted elements, and even
offers an AI bot to make it easier to interact with the stream. Latest Videos From TechRadar Watch full video here: Hardcoded exemptions According to the researchers, the extension is designed to retrieve Twitchs video stream playlists through its own proxy servers. However, instead of simply
forwarding the requests, the extension also attached users OAuth tokens, and since they were placed in the URL, the token also ended up in the proxy servers request logs.
After being called out for it, the extensions developer
(HISHIMIRO/jeetbot.cc) released a new version 85.8.7 (for Firefox, the Chrome one is currently under review) which apparently fixes this flaw: when playlists are retrieved, the users OAuth token is no longer sent to the proxies. It would seem like this was an honest mistake that was remedied upon responsible disclosure. However, here is what Socket had to say about the way the tokens were being retrieved: You may like Hundreds of fake Chrome VPN extensions caught hijacking your traffic That free VPN Chrome and Firefox extension may be reading your clipboard every half a second, researchers warn Security experts warn that Claude for Chrome browser extension could be hijacked
"Current builds (v85.x) forward the token inline as an &auth= query parameter on a network-layer redirect to the operator's proxy," Socket explained. "The token is forwarded for every channel the user watches, except a hardcoded allowlist of ten Russian streamer channels, whose sessions are exempted from forwarding."
If there was a list of 10 Russian streamer channels who were exempt from
OAuth token retrieval, its safe to assume that the developer knew very well what they were doing. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
or sponsors By submitting your information you agree to the Terms &
Conditions and Privacy Policy and are aged 16 or over.
It is good that the extensions were upgraded, but if you are using it, you should also revoke the exposed Twitch token, to be on the safe side.
Via The Hacker News The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/31-000-twitch-users-hit-by-malicious-br owser-extension-oauth-tokens-leaked-via-russian-proxy-network
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)