Twitch Extension Leaked User Tokens to Russian Proxies

A browser add-on designed to enhance viewing experiences quietly exposed the credentials of nearly 31,000 users by routing their private data through third-party servers.
A malicious browser extension for Twitch has leaked OAuth tokens belonging to nearly 31,000 users. These tokens were sent to proxy servers operated by a commercial bot service based in Russia, exposing sensitive user data to potential misuse.
The add-on, named "Twitch Enhanced Viewer | JeetBot," was available on both the Chrome Web Store and Firefox Add-Ons store. It claimed to offer high-quality streaming and region-unlocked content, but its code secretly captured and transmitted user credentials to external servers.
How the token leak occurred
Security researchers from Socket identified that the extension intercepted Twitch’s video playlist requests. Instead of processing these locally, the add-on redirected them through operator-controlled proxies. Crucially, it appended the user’s live OAuth token to these requests as a visible query parameter, effectively handing over the keys to their account.
Because the token was placed in the URL, it was written in cleartext into the proxy server logs. This mechanism applied to every channel a user watched, with a specific exception: a hardcoded list of ten Russian-language streamers was exempted from this data forwarding, suggesting a targeted or selective leak rather than a universal one.
Risks for affected viewers
OAuth tokens are critical credentials that grant access to a user’s Twitch account. In the hands of a malicious actor, these tokens could be used to read private messages, join chats, or alter account settings. The exposure is not limited to public data; it includes the private communication channels that many streamers and viewers rely on for direct interaction.
The operator behind the extension, identified as a Cyprus-based developer, marketed the tool as a powerful bot for Twitch, Kick, and VK Live. The company claims to serve over 26,000 active streamers, but the security implications of its architecture have now placed the privacy of tens of thousands of users at risk.
Remediation and user action
The developer has acknowledged the issue and released version 85.8.7 for Firefox, which stops the token from being sent to proxies. An equivalent update for Chrome is currently under review. According to The Hacker News, users are urged to check their installed version immediately, as older builds continue to transmit sensitive data until updated.
To halt further exposure, affected users should temporarily disable the extension and revoke their current OAuth tokens on Twitch. This step ensures that even if the token was already captured, it can no longer be used to access the account.






