A malicious Twitch browser extension, identified as Twitch Enhanced Viewer | JeetBot, has been discovered forwarding the live OAuth session tokens of approximately 31,000 users to proxy servers operated by a Russian commercial bot service, according to Infosecurity Magazine.The extension, available on both the Chrome Web Store and Firefox Add-ons, claimed to offer features like ad blocking and region unlocking. However, research by Socket revealed that as it routes Twitch video-playlist requests through its own proxy servers, it appends the user's account-scoped OAuth token in cleartext as a URL query parameter. This token, which is not necessary for the extension's advertised functions, grants the holder the ability to read and send whispers, post in chat, and spend channel points without requiring further authentication.Earlier versions of the extension, dating back to January 2026, actively posted captured tokens to a dedicated JeetBot infrastructure endpoint. While later versions shifted to inline forwarding, the lack of disclosure in the extension's data-safety information and privacy policy is a significant concern. Socket advises users to remove the extension, disconnect all active Twitch sessions, and re-authenticate to invalidate any compromised tokens. Security teams are cautioned to treat browser extensions with host permissions and third-party proxy destinations as a credential exposure risk.Source: Infosecurity Magazine
