www.infosecurity-magazine.com 14 Sept 2026, 15:00 UTC

Malicious Twitch Extension Exposed OAuth Tokens From 31,000 Users

Malicious Twitch Extension Exposed OAuth Tokens From 31,000 Users
CyberSIXT Evidence Panel Source marked as original reporting

A malicious Twitch browser extension, Twitch Enhanced Viewer | JeetBot, reportedly exposed the live OAuth session tokens of about 31,000 users, according to research by Socket published on 11 September 2026. The extension was available through both the Chrome Web Store, with approximately 30,000 users, and Firefox Add-ons, with 552 users; both listings were still live when the report was published.

It advertised features including ad blocking, forced 1080p playback and regional unlocking by routing Twitch video-playlist requests through JeetBot proxy servers.

Socket found that the extension appended users’ account-scoped OAuth tokens to proxy requests as URL query parameters, leaving them in clear text in request logs. The researchers said these were broader account tokens rather than limited playback tokens, and demonstrated that they were sent to Twitch’s validation endpoint. As bearer credentials, the tokens could allow whoever obtained them to read and send whispers, post in chat and spend channel points without a password or multi-factor authentication.

Socket said the token was not required for the extension’s advertised functions, and that earlier 4.x versions, including version 4.8 from January 2026, also sent captured tokens to dedicated JeetBot endpoints and two Deno services. Later versions reportedly moved to inline forwarding, with the version number changing from 7.2.6 in April to 85.2.2 in May. Socket advised users to remove the extension, disconnect all Twitch sessions and re-authenticate, which invalidates forwarded tokens.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline