← Back to feed
Vendors & MarketEmerging1 sourceSep 11, 2026 · 14:23via Socket Security Blog

Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service

Brief

Socket’s Threat Research Team identified a cross-store browser extension, “Twitch Enhanced Viewer

  • JeetBot,” that forwards each user’s live Twitch OAuth session token to proxy servers operated by a Russian commercial bot service. The extension ships on both the Chrome Web Store (extension ID pnhhdhhcadcjfckjhpmjneldiegbojfb , 30,000 users) and Firefox Add-ons ( twitchenhancedviewer@example.com , 552 users). Both listings are live at time of writing.
  • Current builds (v85.x) forward the token inline as an &auth= query parameter on a network-layer redirect to the operator's proxy. The token is forwarded for every channel the user watches, except a hardcoded allowlist of ten Russian streamer channels, whose sessions are exempted from forwarding.
Read more on Socket Security Blog→