Skip to content
Malicious Twitch Extension Exposes OAuth Tokens of 31,000 Users

Malicious Twitch Extension Exposes OAuth Tokens of 31,000 Users

First seen 14 Sep 2026, 08:38 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 10:19 UTC
  • The 'Twitch Enhanced Viewer | JeetBot' extension has leaked OAuth tokens from nearly 31,000 users.
  • Tokens are forwarded to Russian-operated proxy servers, compromising user accounts.
  • The extension is still available for download on Chrome and Firefox despite the security risks.

A malicious Twitch browser extension named 'Twitch Enhanced Viewer | JeetBot' has leaked OAuth tokens from nearly 31,000 users to proxy servers operated by a Russian bot service. The extension, available on both Chrome and Firefox, masquerades as a quality-of-life tool for Twitch users, claiming to enhance streaming experiences. It captures OAuth tokens by reading the Authorization header from Twitch's web client and forwards them to the operator's proxy servers, except for a hardcoded list of ten Russian streamer channels. The extension has been downloaded by approximately 30,000 users on Chrome and 604 users on Firefox. The current version forwards tokens as an '&auth=' query parameter, exposing them in cleartext in proxy logs. Previous versions had more aggressive token handling methods. As of now, the extension remains available for download on both platforms.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-06-26
JeetBot extension published on Chrome
The malicious Twitch extension was published on the Chrome Web Store, attracting 30,000 users.
Feeds.Feedburner
2025-07-07
JeetBot extension published on Firefox
The extension was published on the Firefox Add-ons store, with 604 users downloading it.
Feeds.Feedburner
2026-01-01
Version 4.8 released
Earlier builds of the extension were found to POST OAuth tokens to a dedicated endpoint, increasing risk.
Socket.Dev
2026-09-11
Socket.Dev reports on extension
Socket's Threat Research Team identified the malicious behavior of the JeetBot extension.
Socket.Dev
2026-09-14
Current status of extension
Both versions of the JeetBot extension remain available for download, exposing users to risks.
Feeds.Feedburner

More articles in this cluster (3)

Following this threat?

Track JeetBot and Revolut in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed