started · updated
Twitch extension steals OAuth tokens from 30,000 users
A malicious browser extension titled “Twitch Enhanced Viewer | JeetBot” has been identified as stealing OAuth session tokens from tens of thousands of Twitch users. The extension, which advertises features such as ad blocking, forced 1080p playback, and regional stream unlocking, redirects video-playlist requests through infrastructure controlled by the operator.
Security research from Socket reveals that the extension captures the Authorization header used by the Twitch web client and forwards the OAuth token to proxy servers operated by JeetBot, a Russian-language automation and botting service. Because the token is appended as a URL parameter, it can be recorded in plain text within ordinary proxy request logs.
As of mid-September, the extension remains available on both the Chrome Web Store, with approximately 30,000 users, and the Firefox Add-Ons market, with roughly 552 to 600 installations. The stolen account-scoped tokens allow unauthorized parties to bypass passwords and two-factor authentication to access chat, read or send private messages, and modify account settings.
Entities
Chrome Web Store · Firefox Add-Ons · JeetBot · Socket · Twitch