Morning Edition ·
Technology · Cybersecurity SAN FRANCISCO

Malicious Twitch Extension Leaked Login Tokens for 31,000 Viewers

The 'JeetBot' browser add-on funneled OAuth credentials through Russian-linked proxy servers while promising ad-free, high-resolution streams.

Malicious Twitch Extension Leaked Login Tokens for 31,000 Viewers
A laptop displaying lines of code. Photo by Christopher Gower / Unsplash.
SHARE X f in

A browser extension marketed to Twitch viewers as a way to unlock higher-quality, ad-free streams has been quietly leaking users' login credentials to proxy servers tied to a Russian commercial bot service, according to research published this week by security firm Socket. The extension, "Twitch Enhanced Viewer | JeetBot," was installed by nearly 31,000 people combined across the Chrome Web Store and Mozilla's Firefox Add-Ons marketplace before the flaw came to light.

Socket researcher Kush Pandya found that JeetBot routes a user's Twitch video requests through proxy servers operated by its developer in order to deliver the higher-resolution streams it advertises — and in doing so, captures the viewer's logged-in OAuth session token and exposes it to those same proxy operators. Current versions of the extension append the token as a plain query parameter on a network redirect, meaning it gets written in cleartext into the proxy server's own request logs, according to The Hacker News' report on the disclosure.

An OAuth token of this kind is not a password, but it functions as a skeleton key for everything tied to it: TechRadar noted that the leaked tokens could grant access to a victim's Twitch chat, private whispers and account settings. Researchers also identified a hardcoded allowlist inside the extension's code that exempted ten specific Russian streamers from having their tokens forwarded to the proxy network — a detail that suggests the operators built the bypass deliberately rather than as an oversight affecting all users equally.

Roughly 30,000 users exposed on Chrome alone

Of the nearly 31,000 affected installs, about 30,000 came through the Chrome Web Store listing, first published in June 2025, with the remaining 604 installed via Firefox's add-on store starting the following month. The extension's developer, identified in the listing as Aleksandr Popov, acknowledged the token exposure after being contacted by researchers, calling it an oversight tied to a gap in the extension's review process and telling researchers that "the token is a credential and must be protected."

Popov has since released version 85.8.7 for Firefox, which stops forwarding the OAuth token to the proxy network; a corresponding fix for the Chrome version was pending platform review as of this week. Both extensions remained live and installable on their respective stores at the time of the disclosure, and neither Twitch, Google nor Mozilla had issued a public statement addressing the leak.

The incident is a reminder that browser extensions sit largely outside the security scrutiny applied to the platforms they plug into: a Twitch viewer installing JeetBot for a modest quality-of-life upgrade had no straightforward way to know the extension could expose their account credentials to a third party. Security researchers generally advise affected users to revoke third-party app authorizations from their Twitch account settings and uninstall the extension entirely rather than waiting on a patched update, given that the current fix has only shipped for one of the two storefronts involved.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
Claire Fontaine · Technology & Regulation Correspondent

Reports on technology and its regulation for UBStandard, with a focus on Brussels, AI policy and Europe's digital economy.

[email protected]
Related coverage Front page →