Twitch Extension Leaks 31,000 User OAuth Tokens to Russian
A malicious Twitch browser extension forwarded live OAuth tokens for approximately 31,000 users to proxy servers operated by a Russian commercial bot

A malicious browser extension for Twitch has been forwarding live OAuth session tokens belonging to roughly 31,000 users to proxy servers run by a Russian commercial bot service. Security research firm Socket published its findings on September 11, reporting that the extension, Twitch Enhanced Viewer | JeetBot, was available on both the Chrome Web Store and Firefox Add-ons at that time.
Socket's investigation revealed the extension was installed by about 30,000 Chrome users and 552 Firefox users. The listings for the extension remained live following the report's publication.
How the Token Theft Works
The extension presents itself as a utility for improving the Twitch viewing experience. It promises to block advertisements, force 1080p video quality, and unlock region-restricted content. To deliver these features, the extension routes Twitch video-playlist requests through JeetBot's own proxy servers. Socket discovered that during this redirection process, the user's full OAuth token is also sent along.
This token is appended as a plaintext URL query parameter, meaning it is written in clear text into the proxy server's request logs. Socket confirmed this is the account-scoped Twitch OAuth token, not a narrower playback-specific token. The firm proved this by demonstrating the extension sends the identical token value to Twitch's own validation endpoint.
Whoever possesses this bearer token can perform actions on the associated Twitch account without needing a password or two-factor authentication. This includes reading and sending private whispers, posting in chat, and spending channel points.
Evidence of Malicious Intent
Socket's strongest indicator of malicious intent is that the extension has no functional need for the account token. It already handles the playback token separately for its core features. Also, for a hardcoded list of ten Russian-language streamer channels, the extension routes traffic through the same proxy without attaching any account token at all.
Earlier versions of the software were even more brazen. According to Socket, version 4.8 from January 2026 posted captured tokens to a dedicated set-token endpoint on JeetBot infrastructure, with backups stored on two Deno services.
Those older builds implemented tracking for the last token sent and applied a five-second cooldown period. Socket stated this logic only makes sense if the receiving server was actively collecting and storing the tokens. Russian-language comments within the code instructed the extension to fail silently if a token transmission attempt failed.
The dedicated token-collection endpoints were removed in later builds. Socket noted the extension's version number jumped dramatically from 7.2.6 in April to 85.2.2 in May, which is when the current method of inline token forwarding during proxy requests appeared.
Misleading Privacy Disclosures
None of this data collection is disclosed to users. The extension's data-safety section on the Chrome Web Store claims the developer "will not collect or use user data and does not sell it to third parties." Its linked privacy policy similarly states the extension "does not collect, store or process any user data."
Socket has advised affected users to immediately remove the extension. Users should then disconnect all active sessions in their Twitch account settings and re-authenticate, which will invalidate any tokens that were forwarded. The security firm also warned security teams to treat browser extensions that have host permissions over an authenticated service and route traffic through a third-party proxy as a significant credential-exposure risk.
Google, Mozilla, and Twitch were contacted for comment regarding the extension and Socket's findings.





