As cited
Copy frozen at (site build).
cloud saas
Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service
Socket's Threat Research Team discovered a malicious browser extension, "Twitch Enhanced Viewer | JeetBot," distributed across Chrome (30,000 users) and Firefox (552 users) that captures and forwards users' Twitch OAuth session tokens to Russian proxy servers operated by a commercial Twitch bot service. The extension masks token exfiltration as a legitimate quality-of-life tool by routing video requests through operator-controlled proxies, exposing users' account credentials (chat, whispers, channel points) in cleartext server logs. Earlier versions actively collected tokens via dedicated endpoints; current builds append tokens as query parameters on every channel watched except ten hardcoded Russian streamer channels.
Why it matters: Twitch users with this extension installed have their account credentials exposed to an attacker-controlled infrastructure, enabling unauthorized account access, chat impersonation, and financial fraud via channel points; security teams should block the identified infrastructure and malicious extension IDs, and users should immediately remove the extension and re-authenticate their Twitch accounts.
- Source published
- First seen by Cybersecurity Tracker