Malicious Twitch Browser Extension Leaks OAuth Tokens for Nearly 31,000 Users
A malicious browser extension for Twitch, 'Twitch Enhanced Viewer | JeetBot,' has been discovered leaking OAuth tokens for almost 31,000 users to servers operated by a Russian bot service.

A malicious browser extension designed to enhance the Twitch viewing experience has been found to be exfiltrating sensitive OAuth tokens from nearly 31,000 users. The extension, identified as 'Twitch Enhanced Viewer | JeetBot,' was available on both the Google Chrome Web Store and the Mozilla Firefox Add-Ons store, broadening its potential reach.
The stolen OAuth tokens, which grant access to user accounts without requiring passwords, were reportedly sent to proxy servers managed by a Russian commercial bot service. This type of data theft can have severe consequences, allowing attackers to impersonate users, access private messages, and potentially perform unauthorized actions on behalf of the compromised accounts.
Details regarding the specific vulnerabilities exploited by the extension are still emerging, but the method of data exfiltration suggests a deliberate design for malicious purposes. The extension's presence on official browser extension marketplaces indicates a sophisticated attempt to bypass security checks and gain user trust.
Security researchers who uncovered the malicious activity have alerted both Google and Mozilla to the presence of the harmful extension. Users who have installed 'Twitch Enhanced Viewer | JeetBot' are strongly advised to revoke its access immediately and change their Twitch account passwords as a precautionary measure. Furthermore, it is recommended that users review their connected applications and revoke access for any unfamiliar or suspicious entries.
The incident highlights the ongoing risks associated with third-party browser extensions, even those hosted on official platforms. Users are reminded to exercise caution when installing extensions, to scrutinize developer information, and to regularly review the permissions granted to installed add-ons.
While the exact number of affected users is estimated at nearly 31,000, the true impact could be wider if the stolen tokens are exploited for further malicious activities. The involvement of a Russian commercial bot service suggests a potential for large-scale credential stuffing or account takeovers.
This incident underscores the importance of robust security vetting processes for browser extension marketplaces. Developers and platform providers must continually enhance their detection mechanisms to prevent malicious software from reaching end-users and compromising their online security.
As investigations continue, further details about the threat actor's motives and the full extent of the data compromise are expected. The security community is monitoring the situation closely to understand the broader implications and to develop effective countermeasures.