Skip to content
Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens

Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens

Infosecurity-Magazine September 14, 2026

A malicious Twitch browser extension has been reportedly forwarding the live OAuth session tokens of around 31,000 users to proxy servers run by a Russian commercial bot service, according to Socket.

The cross-store browser extension Twitch Enhanced Viewer | JeetBot was live on both the Chrome Web Store and Firefox Add-ons when Socket published its research on September 11, with 30,000 Chrome users and 552 on Firefox.

The listings are still live at the time of writing.

A Token the Extension Does Not Need

The extension markets itself as a quality-of-life tool, blocking ads, forcing 1080p and unlocking regions. Delivering that means routing Twitch video-playlist requests through JeetBot proxy servers, and Socket found the user's OAuth token rides along on the redirect.

The OAuth token is appended as a URL query parameter, so it is written in cleartext into the proxy's request logs. Socket said it is the account-scoped Twitch token rather than the narrow playback token, and proved it by showing the extension sends the same value to Twitch's own validation endpoint.

That credential is a bearer token. Whoever holds it can read and send whispers, post in chat and spend channel points on the account, without requiring a password or second factor authentication.

Socket's strongest evidence on intent is that the extension does not need the token to work. It already handles the playback token separately, and for a hardcoded list of 10 Russian-language streamer channels it routes traffic through the same proxy with no account token attached at all.

Earlier Builds Stored the Tokens

Version 4.x builds went further. Socket said version 4.8, from January 2026, posted captured tokens to a dedicated set-token endpoint on JeetBot infrastructure, with backups on two Deno services.

Those builds tracked the last token sent and applied a five-second cooldown, which Socket said only makes sense if the receiving server was keeping them. Russian-language in the code instruct the extension to fail silently if a token send does not go through.

The set-token endpoints are gone from later builds, and Socket noted the version number jumped from 7.2.6 in April to 85.2.2 in May, when the inline forwarding appeared.

Socket told users to remove the extension, then disconnect all sessions in Twitch account settings and re-authenticate, which invalidates any forwarded token. It told security teams to treat browser extensions holding host permissions over an authenticated service, combined with a third-party proxy destination, as a credential-exposure risk.

Google, Mozilla and Twitch were approached for . This article will be updated with any response.

Malicious Chrome Extensions Campaign Exposes User Data News 14 April 2026

Malicious Chrome Extensions Campaign Exposes User Data

Shai-Hulud-Like Worm Targets Developers via npm and AI Tools News 23 February 2026

Shai-Hulud-Like Worm Targets Developers via npm and AI Tools

npm Package Uses QR Code Steganography to Steal Credentials News 24 September 2025

npm Package Uses QR Code Steganography to Steal Credentials

Npm Supply Chain Malware Attack Targets Developers With Worm-Like Propagation News 24 April 2026

Npm Supply Chain Malware Attack Targets Developers With Worm-Like Propagation

Mini Shai-Hulud Hits Hundreds of npm Packages in AntV Ecosystem News 20 May 2026

Mini Shai-Hulud Hits Hundreds of npm Packages in AntV Ecosystem

What’s Hot on Infosecurity Magazine?

CISA Updates Insider Threat Guide With New Mitigation Advice

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls

Anthropic Reveals Yet Another Cybersecurity Incident

MantaxOtax Android Malware Combines Ransomware With Spyware

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Anthropic Reveals Yet Another Cybersecurity Incident

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

NCSC Warns Shadow AI Creates New Security Risks

AI Coding Tools Now a Prime Target for Threat Actors, Google Warns

Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

How to Manage Enterprise Cyber Resilience in the Age of AI

How To Enhance Security Operations with AI-Powered Defenses

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust