An extension called Twitch Enhanced Viewer | JeetBot, listed in both the Chrome Web Store and the Firefox Add-ons catalogue and installed more than 30,000 times, captures Twitch users' OAuth session tokens and forwards them through proxy servers operated by a commercial Russian-language bot service, according to analysis by the software supply-chain security firm Socket. The extension markets itself as a legitimate third-party tool that blocks ads, forces 1080p playback, bypasses regional restrictions and collects channel points; in practice it reads the authorisation header used by the Twitch web client, extracts the user's OAuth token and appends it to redirected proxy requests as an auth= query parameter, which writes the credential in cleartext into the proxy server's request logs where the operator can retrieve it. The behaviour occurs for every channel a user watches except ten Russian-language channels hardcoded into the extension, and Socket reports that earlier builds used more explicit credential-theft mechanisms โ a point the developer effectively conceded in the Firefox listing's own disclaimer, which states that previous versions transmitted the OAuth token to their server. The Chrome listing's data disclosure claims the developer does not collect or use user data. At the time of publishing both extensions remained available for download. Socket's guidance is to remove the extension, disconnect all Twitch sessions and re-authenticate to invalidate any token already forwarded. The story's relevance extends beyond Twitch: the mechanism is a third-party dependency being trusted because it appears in a curated store catalogue, which is the same assumption that made today's Reddit malvertising effective and is the reason store review, not user vigilance, is the load-bearing control.
| Attribute | Detail |
|---|---|
| Sector | Retail & Entertainment & Sport |
| Date | 2026-09-15 |
| Source | BleepingComputer |
| Reliability | Tier 2 |