A malicious browser extension designed to enhance the Twitch viewing experience has exposed the OAuth session tokens of nearly 31,000 users by sending them through proxy servers controlled by its operator.

The extension, called “Twitch Enhanced Viewer | JeetBot,” is available on both the Google Chrome Web Store and Mozilla Firefox Add-ons store. The Chrome version has around 30,000 users, while the Firefox version has another 604 users. Both versions were still available for download when the issue was reported.

The extension claims to provide features such as ad-free viewing and access to 1080p streams in regions where Twitch places restrictions. However, researchers found that the extension was also extracting users’ Twitch OAuth tokens and forwarding them to operator-controlled proxy servers whenever they watched most channels.

According to security researcher Kush Pandya, the current version places the OAuth token directly into a URL as an auth parameter when redirecting Twitch video requests through the proxy. This means the credential can also end up being recorded in the proxy server’s request logs.

A Twitch OAuth token is particularly sensitive because it can provide access to parts of a user’s account without requiring their password or another authentication step. Depending on the permissions attached to the token, it can allow access to chat, private messages known as whispers, account settings and other account actions.

Researchers also found that the token-forwarding behavior was not applied to 10 channels that were included in the extension’s playback workaround. Most of those channels were Russian-language streamers. The list was later found to be configurable by users rather than being a permanent exemption built into the extension.

READ
Tech Support Scams in 2026: Everything You Need to Know

Earlier versions of the extension reportedly used an even more direct approach, sending the token to a dedicated endpoint on the operator’s servers.

The developer behind JeetBot has since changed the extension’s implementation. Version 85.8.7 of the Firefox add-on no longer sends Twitch OAuth tokens to the proxy servers, while an equivalent Chrome update had been submitted for review. Users running older versions were advised to update immediately.

Importantly, simply disabling or updating the extension does not revoke OAuth tokens that were already transmitted. Users who had the affected versions installed may therefore need to take additional steps to invalidate previously exposed credentials.

JeetBot’s developer, Aleksandr Popov, said the token forwarding was an oversight related to how the extension retrieved Twitch stream playlists. He acknowledged that the previous privacy policy and extension description did not adequately disclose that OAuth tokens were being transmitted to the company’s proxy servers.

Popov disputed the characterization of the extension as malicious, saying its purpose was to provide playback functionality and that the tokens were not intended for unauthorized account activity. He nevertheless acknowledged the security risk and said the design had been changed so the tokens no longer need to be forwarded.


Buy ExpressVPN with PayPal or Credit Card

Security researchers estimate that approximately 31,000 Chrome and Firefox users had their live Twitch OAuth session tokens routed through the operator’s proxy infrastructure. Because these tokens function as bearer credentials, anyone possessing one could potentially perform account actions without knowing the user’s password.

READ
Microsoft Warns of AI-Powered Invoice Fraud and Passkey Attacks
Advertisement