News

Twitch JeetBot extension leaks OAuth tokens for 31k users

Socket Threat Research (11 September 2026) says the Twitch Enhanced Viewer JeetBot extension forwarded live Twitch OAuth tokens from about 30,000 Chrome users and 552 Firefox users. Tokens skipped a hardcoded list of ten Russian streamer channels.

Twitch JeetBot extension leaks OAuth tokens for 31k users

Socket Threat Research (Kush Pandya, 11 September 2026) documented a Chrome and Firefox extension, Twitch Enhanced Viewer | JeetBot, that forwards each user's live Twitch OAuth session token through proxies run by a commercial bot service. The Chrome Web Store listing (ID pnhhdhhcadcjfckjhpmjneldiegbojfb) showed about 30,000 users. Firefox Add-ons showed about 552 users. Both listings were live when Socket published.

This is a Socket technical write-up on a third-party store extension. It is not a Twitch platform breach, not a CVE advisory, and not a law-enforcement takedown. Store user counts are listings at research time and can change.

The extension markets itself as an ad-block, 1080p, region-unlock, and channel-points helper. To deliver video, current v85.x builds redirect Twitch playlist requests (usher.ttvnw.net) through operator-controlled proxies and append the user's Twitch OAuth token as an &auth= query parameter.

Socket shows that token is the account-scoped OAuth credential (chat, whispers, account settings), not a narrow stream-playback token. The extension validates it against Twitch's own token-validation endpoint with an Authorization: OAuth header. The token is forwarded for every channel watched except a hardcoded allowlist of ten Russian streamer channels.

The operator is described as a commercial Twitch, Kick, and VK Live bot SaaS that relays live authenticated sessions through its infrastructure. Developer credit on the stores is HISHIMIRO / jeetbot.cc. Earlier builds collected tokens more outright, including a POST to a set-token endpoint. Socket maps the capture path through content.js and background.js, with a default proxy at enhanced.jeetbot.cc, a forced-strip proxy at morphilina.me, and a proxy catalog at ext-styles.jeetbot.cc.

The Hacker News (14 September 2026) later put the Firefox listing at 604 users and said both stores still offered the add-on. The operator told that outlet the token forwarding was an oversight, that Firefox 85.8.7 stops sending the OAuth token to proxies, and that a Chrome build was still in store review. Socket's 11 September analysis treated then-current v85.x listings as still appending the token.

Related credential-theft tape includes Microsoft passkey lures into Microsoft 365 cloud theft and the Sogou UNC3569 GrayRabbit one-click chain.

If you use Twitch in a browser, remove Twitch Enhanced Viewer / JeetBot, revoke every Twitch session, and treat any region-unlock or ad-free Twitch add-on as hostile until the publisher is one you have verified yourself.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free