Top Highlights
- A Twitch browser extension named "JeetBot" has leaked approximately 31,000 users’ OAuth tokens to Russian-controlled proxy servers, enabling potential unauthorized access to chat, private messages, and account settings.
- The extension retrieves OAuth tokens by embedding them in URL query parameters sent to operator-controlled proxies, which logs these tokens in plaintext, exposing sensitive credentials.
- Although an update (version 85.8.7) has addressed the token leakage, many users remain vulnerable until they upgrade, risking account hijacking, spying, or malicious activity.
Threat Overview, Techniques, and Targets
A malicious Twitch browser extension called “Twitch Enhanced Viewer | JeetBot” has leaked OAuth tokens of nearly 31,000 users. The extension appears legitimate and promises enhanced viewing and streaming features. However, it secretly captures user tokens and sends them to proxy servers run by a Russian bot service. The extension embeds code that recovers OAuth tokens and forwards them via URLs with an “&auth=” query parameter. This process is part of redirecting Twitch video playlist requests. The extension is available on both Google Chrome Web Store and Mozilla Firefox Add-Ons, and both are still accessible. The extension targets Twitch users, especially streamers and viewers seeking features like ad-free content and region unlocking. It also accesses users’ chat, private messages, and account settings by capturing OAuth tokens. The attacker’s infrastructure is operated by a service that has broad permissions over Twitch, Kick, and VK-Live.
Impact, Security Risks, and Remediation
The leak of OAuth tokens exposes users to significant security risks. Anyone with a token can access a user’s Twitch account. This includes reading and sending private messages, chatting, or spending channel points. In addition, tokens in logs can be stolen and misused. The extension’s operator runs a bot SaaS that relays live sessions through its infrastructure. Although the developers have issued an update (version 85.8.7) to fix the problem, older versions still send tokens. Users are advised to update the extension to the latest version immediately. If an update is not yet available, users should disable the extension temporarily. It is also important to remember that disabling or updating the extension does not revoke previously transmitted tokens. For detailed guidance and further assistance, users should consult the relevant vendor or authority.
Stay Ahead with the Latest Tech Trends
Learn how the Internet of Things (IoT) is transforming everyday life.
Discover archived knowledge and digital history on the Internet Archive.
ThreatIntel-V1
