Feeds.Feedburner Malicious Twitch Extension Exposes OAuth Tokens of 31,000 Users
Article Content
- •The 'Twitch Enhanced Viewer | JeetBot' extension has leaked OAuth tokens from nearly 31,000 users.
- •Tokens are forwarded to Russian-operated proxy servers, compromising user accounts.
- •The extension is still available for download on Chrome and Firefox despite the security risks.
A malicious Twitch browser extension named 'Twitch Enhanced Viewer | JeetBot' has leaked OAuth tokens from nearly 31,000 users to proxy servers operated by a Russian bot service. The extension, available on both Chrome and Firefox, masquerades as a quality-of-life tool for Twitch users, claiming to enhance streaming experiences. It captures OAuth tokens by reading the Authorization header from Twitch's web client and forwards them to the operator's proxy servers, except for a hardcoded list of ten Russian streamer channels. The extension has been downloaded by approximately 30,000 users on Chrome and 604 users on Firefox. The current version forwards tokens as an '&auth=' query parameter, exposing them in cleartext in proxy logs. Previous versions had more aggressive token handling methods. As of now, the extension remains available for download on both platforms.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track JeetBot and Revolut in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…