Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service
Brief
Socket’s Threat Research Team identified a cross-store browser extension, “Twitch Enhanced Viewer
- JeetBot,” that forwards each user’s live Twitch OAuth session token to proxy servers operated by a Russian commercial bot service. The extension ships on both the Chrome Web Store (extension ID pnhhdhhcadcjfckjhpmjneldiegbojfb , 30,000 users) and Firefox Add-ons ( twitchenhancedviewer@example.com , 552 users). Both listings are live at time of writing.
- Current builds (v85.x) forward the token inline as an &auth= query parameter on a network-layer redirect to the operator's proxy. The token is forwarded for every channel the user watches, except a hardcoded allowlist of ten Russian streamer channels, whose sessions are exempted from forwarding.
