StratosAlly – Cybersecurity for digital safety

31,000 Twitch Users at Risk After Malicious Extension Steals OAuth Tokens

Picture of StratosAlly

StratosAlly

31,000 Twitch Users at Risk After Malicious Extension Steals OAuth Tokens

A browser extension promising Twitch users a better viewing experience may have quietly put their accounts at risk.

Security researchers at Socket have uncovered a malicious version of “Twitch Enhanced Viewer | JeetBot,” a cross-browser extension available through both the Google Chrome Web Store and Mozilla Firefox Add-ons. The extension has been downloaded by nearly 31,000 users—around 30,000 on Chrome and 604 on Firefox.

The extension advertised features such as ad-free viewing, region-unlocked streams and 1080p playback. But behind the scenes, it was extracting users’ Twitch OAuth session tokens and sending them through proxy servers controlled by the extension’s operator.

The problem is particularly serious because these tokens act like authentication credentials. Anyone possessing a valid token could potentially access a user’s Twitch chat, private whispers and account settings without needing the account password or a second authentication factor.

Researchers found that the extension placed the OAuth token directly into a URL as an auth parameter while routing Twitch video requests through operator-controlled infrastructure. Because URLs can be recorded in server logs, the tokens could remain exposed in plaintext.

There was also an unusual exception: token forwarding was disabled for 10 specific Twitch channels, most of them associated with Russian-language streamers. For virtually every other channel, the user’s active token was forwarded to the proxy.

Earlier versions reportedly went even further, sending tokens directly to an operator-controlled endpoint.

The extension is associated with JeetBot, a commercial bot service for Twitch, Kick and VK Live. The service claims more than 26,000 active streamers and one billion processed messages.

The developer has since acknowledged the issue and released Firefox version 85.8.7, which stops sending OAuth tokens to its proxy servers. A corresponding Chrome update was reportedly still under review at the time of publication.

However, there is an important catch: updating or disabling the extension does not revoke tokens that were already exposed. Users who installed it should update immediately and consider revoking their Twitch sessions/tokens as an additional precaution.

Let’s refine your stalking skills; go through our Instagram and LinkedIn.

more Related articles