Twitch Extension with 30,000 Installs Exposes Users’ OAuth Tokens
A disturbing trend has emerged on Twitch, one of the world’s most popular live streaming platforms. A browser extension called Twitch Enhanced Viewer | JeetBot, available in both Chrome and Firefox stores, has been sending users’ sensitive OAuth session tokens to a commercial bot service without their consent. This has left thousands of users vulnerable to potential identity theft and account compromise.
The extension, which boasts over 30,000 installs, was advertised as a legitimate third-party tool for Twitch that could block ads, force full HD playback, bypass region restrictions, and enable channel-point collection. However, a closer look at the extension’s behavior reveals a more sinister purpose. According to an analysis by application security company Socket, the extension captures the authorization header used by the Twitch web client and extracts the user’s OAuth token. This token is then sent through proxy servers operated by JeetBot, a commercial Russian-language streaming and chatbot service.
The process works as follows: when the user watches a Twitch channel, the extension redirects the video playlist request to usher.ttvnw[.]net through a proxy server. The token is appended directly to the redirected request as an &auth= query parameter, making it easily accessible in the proxy server’s logs. This means that every time a user watches a Twitch channel using this extension, their OAuth token is being sent to JeetBot’s servers.
Socket highlights that earlier versions of the extension included more explicit credential-theft mechanisms. In fact, the developer had previously stated in the product description that it would transmit users’ OAuth tokens to its server for “streaming functionality.” However, this statement was later removed, and the developer claimed to have updated the extension to no longer collect or use user data.
The presence of Twitch Enhanced Viewer | JeetBot in both Chrome and Firefox stores is a concern. At the time of writing, the extension was still available for download from these platforms. BleepingComputer has reached out to JeetBot for additional information but received no response by publication.
Users are advised to remove this extension from their browsers immediately, disconnect all sessions in Twitch, and re-authenticate to invalidate any tokens that may have been forwarded. Developers are also cautioned against routing requests with authentication headers or tokens through third-party servers.
This incident serves as a reminder of the importance of carefully reviewing the permissions and behavior of browser extensions before installing them. With thousands of potential vulnerabilities lurking on online marketplaces, it’s crucial for users to stay vigilant and prioritize their online security.
Source: Bleeping Computer — 2026-09-14