Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2815+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
NEWS

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

"Twitch Enhanced Viewer | JeetBot" forwarded OAuth tokens in cleartext to a Russian bot service's proxy, exposing roughly 31,000 users.

Dylan H.

News Desk

September 14, 2026
3 min read

A "Viewer Enhancement" Extension That Phones Home

A malicious cross-store browser extension called "Twitch Enhanced Viewer | JeetBot" has leaked OAuth tokens belonging to nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension is listed under developer HISHIMIRO/jeetbot.cc, reportedly operated by Cyprus-based Aleksandr Popov.


Distribution Footprint

StoreListing IDPublishedUsers
Chrome Web StorepnhhdhhcadcjfckjhpmjneldiegbojfbJune 26, 2025~30,000
Firefox Add-onstwitchenhancedviewer@example.comJuly 7, 2025604

Despite the modest Firefox footprint, the Chrome listing alone accounts for the bulk of the roughly 31,000 combined affected users.


How Tokens Leaked

According to security researcher Kush Pandya, current builds (v85.x) forward the user's OAuth token inline as an &auth= query parameter on a network-layer redirect to the operator's proxy infrastructure. That places live authentication tokens directly in server request logs as cleartext data — readable by anyone with access to those logs, not just the extension's own backend.

The extension is tied to JeetBot, a commercial bot service marketed for Twitch, Kick, and VK Live streaming platforms, which claims more than 26,000 active streamers as customers.


Why This Matters

An OAuth token grants the same access as a login session without needing a password — meaning anyone in possession of a leaked token can act on the victim's Twitch account: read private data, post as the user, or pivot into connected integrations, until the token is revoked.


Remediation Is Incomplete

Users are urged to update to version 85.8.7 or newer on Firefox, or the equivalent updated build on Chrome. However, the developer itself cautioned that "disabling or updating the extension does not revoke previously transmitted tokens" — meaning every user who ran a vulnerable build should treat their Twitch account as potentially compromised regardless of whether they've since updated.


Recommended Actions

  1. Uninstall the extension if you have it installed on any browser.
  2. Revoke and regenerate your Twitch OAuth authorization via Twitch account settings — updating the extension alone does not invalidate already-leaked tokens.
  3. Change your Twitch password and enable two-factor authentication if not already active.
  4. Review connected third-party apps on your Twitch account for anything unrecognized.
  5. Be cautious of "enhancement" browser extensions for streaming platforms — verify publisher reputation and review requested permissions before installing.

Related Reading

  • Social Media Scams Cost Americans Over $21 Billion in 2025
  • Popular node-ipc npm Package Compromised to Steal Credentials
#Russia#Data Breach#Browser Extension#Twitch#OAuth

Related Articles

Scope of Salesforce Attacks Expands as Icarus Leaks Stolen Data

More victims have surfaced after attackers breached application vendor Klue and abused its OAuth tokens to access customers' Salesforce environments. The...

4 min read

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Researchers at Guardio disclosed a now-patched vulnerability chain in the Adobe Acrobat Chrome extension dubbed HermeticReader, which could allow...

4 min read

Edgecution: Malicious Edge Extension Escapes Browser Sandbox via Native Messaging

A malicious Microsoft Edge extension dubbed 'Edgecution' abused the Native Messaging API to escape the browser sandbox and deliver a Python backdoor used...

4 min read
Back to all News