CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7100

As cited

Copy frozen at (site build).

cloud saas

Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service

Socket's Threat Research Team discovered a malicious browser extension, "Twitch Enhanced Viewer | JeetBot," distributed across Chrome (30,000 users) and Firefox (552 users) that captures and forwards users' Twitch OAuth session tokens to Russian proxy servers operated by a commercial Twitch bot service. The extension masks token exfiltration as a legitimate quality-of-life tool by routing video requests through operator-controlled proxies, exposing users' account credentials (chat, whispers, channel points) in cleartext server logs. Earlier versions actively collected tokens via dedicated endpoints; current builds append tokens as query parameters on every channel watched except ten hardcoded Russian streamer channels.

Why it matters: Twitch users with this extension installed have their account credentials exposed to an attacker-controlled infrastructure, enabling unauthorized account access, chat impersonation, and financial fraud via channel points; security teams should block the identified infrastructure and malicious extension IDs, and users should immediately remove the extension and re-authenticate their Twitch accounts.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary