Back Infosecurity-Magazine Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens
A malicious Twitch browser extension has been reportedly forwarding the live OAuth session tokens of around 31,000 users to proxy servers run by a Russian commercial bot service, according to Socket.
The cross-store browser extension Twitch Enhanced Viewer | JeetBot was live on both the Chrome Web Store and Firefox Add-ons when Socket published its research on September 11, with 30,000 Chrome users and 552 on Firefox.
The listings are still live at the time of writing.
A Token the Extension Does Not Need
The extension markets itself as a quality-of-life tool, blocking ads, forcing 1080p and unlocking regions. Delivering that means routing Twitch video-playlist requests through JeetBot proxy servers, and Socket found the user's OAuth token rides along on the redirect.
The OAuth token is appended as a URL query parameter, so it is written in cleartext into the proxy's request logs. Socket said it is the account-scoped Twitch token rather than the narrow playback token, and proved it by showing the extension sends the same value to Twitch's own validation endpoint.
That credential is a bearer token. Whoever holds it can read and send whispers, post in chat and spend channel points on the account, without requiring a password or second factor authentication.
Socket's strongest evidence on intent is that the extension does not need the token to work. It already handles the playback token separately, and for a hardcoded list of 10 Russian-language streamer channels it routes traffic through the same proxy with no account token attached at all.
Earlier Builds Stored the Tokens
Version 4.x builds went further. Socket said version 4.8, from January 2026, posted captured tokens to a dedicated set-token endpoint on JeetBot infrastructure, with backups on two Deno services.
Those builds tracked the last token sent and applied a five-second cooldown, which Socket said only makes sense if the receiving server was keeping them. Russian-language in the code instruct the extension to fail silently if a token send does not go through.
The set-token endpoints are gone from later builds, and Socket noted the version number jumped from 7.2.6 in April to 85.2.2 in May, when the inline forwarding appeared.
Socket told users to remove the extension, then disconnect all sessions in Twitch account settings and re-authenticate, which invalidates any forwarded token. It told security teams to treat browser extensions holding host permissions over an authenticated service, combined with a third-party proxy destination, as a credential-exposure risk.
Google, Mozilla and Twitch were approached for . This article will be updated with any response.
Malicious Chrome Extensions Campaign Exposes User Data News 14 April 2026
Malicious Chrome Extensions Campaign Exposes User Data
Shai-Hulud-Like Worm Targets Developers via npm and AI Tools News 23 February 2026
Shai-Hulud-Like Worm Targets Developers via npm and AI Tools
npm Package Uses QR Code Steganography to Steal Credentials News 24 September 2025
npm Package Uses QR Code Steganography to Steal Credentials
Npm Supply Chain Malware Attack Targets Developers With Worm-Like Propagation News 24 April 2026
Npm Supply Chain Malware Attack Targets Developers With Worm-Like Propagation
Mini Shai-Hulud Hits Hundreds of npm Packages in AntV Ecosystem News 20 May 2026
Mini Shai-Hulud Hits Hundreds of npm Packages in AntV Ecosystem
What’s Hot on Infosecurity Magazine?
CISA Updates Insider Threat Guide With New Mitigation Advice
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
Anthropic Reveals Yet Another Cybersecurity Incident
MantaxOtax Android Malware Combines Ransomware With Spyware
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Anthropic Reveals Yet Another Cybersecurity Incident
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
NCSC Warns Shadow AI Creates New Security Risks
AI Coding Tools Now a Prime Target for Threat Actors, Google Warns
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
How to Manage Enterprise Cyber Resilience in the Age of AI
How To Enhance Security Operations with AI-Powered Defenses
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
