Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

Malicious JeetBot Twitch extension leaks OAuth tokens of 31,000 users to third-party proxy servers

Cahyo Dewo, September 14, 2026

A significant security vulnerability has been identified within the browser extension known as Twitch Enhanced Viewer, marketed under the name JeetBot. The extension, which is available on both the Google Chrome Web Store and the Mozilla Firefox Add-Ons store, was discovered to be surreptitiously harvesting and transmitting sensitive OAuth authentication tokens from approximately 31,000 active users to external, operator-controlled proxy servers. These tokens, which act as digital "keys" to a user’s Twitch account, were being funneled to infrastructure managed by a commercial bot service provider, raising serious concerns regarding user privacy, account hijacking, and the broader security implications of third-party browser plugins.

The security researchers at Socket, who first disclosed the findings, noted that the extension was systematically logging user credentials in cleartext within the proxy server’s request logs. While the developer, Aleksandr Popov, has since initiated updates to address the flaw, the incident highlights a persistent and growing threat within the ecosystem of browser extensions, where tools promising convenience or quality-of-life enhancements often bypass rigorous security scrutiny.

Anatomy of the Security Breach

The core functionality of the JeetBot extension—which claims to provide users with 1080p stream quality, region-unlocked content, and an ad-free viewing experience—relied on a technical workaround to bypass Twitch’s standard video-playlist request protocols. To achieve this, the extension routed traffic to Twitch’s video delivery domain, usher.ttvnw.net, through the developer’s own proxy infrastructure.

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

Crucially, the extension was designed to append the user’s active Twitch OAuth token as an &auth= query parameter during this redirection process. Because this data was passed via a URL query string, the credentials were written directly into the proxy server’s access logs. An OAuth token is a powerful bearer credential; if intercepted, it grants a malicious actor the ability to perform actions on behalf of the user, including reading private messages (whispers), participating in chat, and managing account settings, all without the need for a password or multi-factor authentication (MFA).

The research indicated that this behavior was not a temporary glitch but a deliberate architectural choice in version 85.x of the extension. Furthermore, earlier iterations, such as version 4.8, exhibited even more aggressive data harvesting behaviors, including explicitly POSTing tokens to dedicated endpoints on the operator’s host, with redundant backups stored on platforms like deno.dev and deno.net.

The Geography of Exemption: A Selective Bypass

One of the more peculiar aspects of the JeetBot vulnerability was the implementation of a hardcoded "allowlist." For a specific set of ten Twitch channels—predominantly Russian-language streamers with large followings—the extension bypassed the token-forwarding mechanism.

According to the developer, this was not a security feature but rather a functional workaround for a specific error known as "Error #3," which users often encountered when attempting to view restricted content while using a VPN or proxy. The developer asserted that this specific playback path did not require the token to be sent to the proxy. However, the optics of such an exemption, particularly given that the developer is based in Cyprus and the service has strong ties to Russian-language streaming communities, raised questions about the potential for preferential treatment or internal testing protocols.

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

Timeline of the Discovery and Response

The exposure was uncovered by security analysts at Socket, who monitored the extension’s network-layer activity and identified the pattern of exfiltration. The timeline of the incident can be summarized as follows:

  • January 2026 (Version 4.x): Early builds of the extension actively POSTed OAuth tokens to a centralized endpoint, demonstrating an established intent to collect user session data.
  • Ongoing (Version 85.x): The extension transitioned to the &auth= query parameter method, silently leaking tokens for every channel viewed that was not on the "allowlist."
  • Discovery: Researchers at Socket analyzed the extension’s code and network traffic, identifying the 31,000-user impact.
  • Disclosure: The findings were made public, pressuring the developer to issue a patch.
  • Immediate Remediation: The developer updated the documentation and released version 85.8.7, which ostensibly removes the token-forwarding functionality.
  • Post-Patch Status: While updates are available, the developer has acknowledged that simply updating the extension does not retroactively revoke the tokens that have already been transmitted to the proxy servers.

Official Response and Developer Justification

In an interview with The Hacker News, Aleksandr Popov, the developer behind JeetBot, admitted that the handling of OAuth tokens was an "oversight" that lacked adequate transparency in the extension’s privacy policy. Popov emphasized that the intention behind the design was to facilitate playback functionality rather than to engage in malicious account compromise.

Popov argued that the practice of proxying tokens is relatively common in the niche ecosystem of Twitch playback extensions. He specifically cited other extensions, such as ReYohoho and XT Viewer, which he claimed employ similar methods. However, he acknowledged that those competitors were more transparent about their data practices in their store listings, whereas JeetBot failed to properly inform its user base.

"We recognize the security risk of the previous design," Popov stated. "We have taken those concerns seriously and changed the extension’s implementation. We acknowledge that the previous description and privacy policy did not adequately explain the transmission of Twitch OAuth tokens to our proxy servers."

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

Broader Implications for Browser Security

The JeetBot incident serves as a stark reminder of the risks associated with "power-user" browser extensions. These tools often request high-level permissions to read and modify data on specific websites. When users install such extensions, they are essentially granting the developer the ability to intercept any request made to that domain.

The implications for the 31,000 affected users are significant. Because an OAuth token is a session-based credential, it does not necessarily expire immediately when an extension is disabled. While many users may assume that deleting a malicious extension solves the problem, the reality is that the token currently residing on the developer’s server remains valid until the user explicitly logs out of Twitch, which invalidates the existing session token.

Security experts recommend that users who have installed JeetBot or similar third-party playback tools take the following steps immediately:

  1. Revoke Sessions: Users should go to their Twitch account settings, navigate to "Security and Privacy," and review "Connected Apps" or "Sessions," choosing to log out of all active sessions to force a token refresh.
  2. Change Passwords: As a precautionary measure, updating the account password is advised to prevent future unauthorized access.
  3. Audit Permissions: Users should audit their browser extensions and remove any that are not strictly necessary, particularly those that require extensive site-access permissions.

The "Botting" Industry Context

JeetBot represents a wider industry of third-party SaaS (Software as a Service) providers that cater to streamers seeking to boost their analytics, manage chat, or automate content delivery. With over 26,000 active streamers and claims of having processed over one billion messages, JeetBot is a significant player in this unregulated space.

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

The use of proxy infrastructure to "unblock" content or optimize stream quality is a double-edged sword. While it provides functionality that some users desire, it creates a "man-in-the-middle" scenario where the proxy operator holds total control over the traffic. In this case, the centralization of user data on a proxy server created a "honeypot" for credentials.

The incident also highlights a failure in the vetting processes of major browser stores. Despite the clear presence of code designed to exfiltrate session tokens, the extension remained available to thousands of users for an extended period. As browser vendors continue to tighten their security models—such as the transition to Manifest V3 in Chrome—the ability of extensions to perform such intrusive actions is expected to be more strictly limited. However, until such enforcement becomes absolute, the responsibility for security remains largely with the end-user.

In conclusion, the JeetBot case is a cautionary tale regarding the "convenience vs. security" trade-off. While the developer has moved to remediate the specific vulnerability, the event has eroded trust in the extension and raised alarms about the thousands of similar tools currently operating in the shadows of the web. Users are urged to exercise extreme caution when installing any tool that promises to bypass regional restrictions or enhance platform capabilities, as the cost of such features can often be the total compromise of their digital identity.

Cybersecurity & Digital Privacy CybercrimeextensionHackingjeetbotleaksmaliciousoauthpartyPrivacyproxySecurityServersthirdtokenstwitchusers

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes