Find notable cyber news and cases, enriched with sources, timelines, and signals.

Twitch Enhanced Viewer | JeetBot OAuth token leak

Data Leak
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

A malicious Twitch browser extension exposed OAuth bearer tokens for nearly 31,000 users, creating account-takeover risk across chat, whispers, account settings, and channel points. The add-on, Twitch Enhanced Viewer | JeetBot, forwarded the tokens to operator-controlled proxy servers using an `&auth=` parameter. The exposed credentials came from Chrome and Firefox builds published in 2025. A documented update to version 85.8.7 stops the token forwarding, but previously transmitted tokens are not revoked.

Related Happenings

Twitch Enhanced Viewer | JeetBot OAuth token-stealing extension

Malware Activity
H score35 First: 14.09.2026 10:24 Last: 14.09.2026 10:24 Sources 1

How related: Specifically, the add-on embeds code to recover the Twitch OAuth token and send it to the proxy.

About this happening: Twitch Enhanced Viewer | JeetBot is leaking Twitch OAuth tokens through operator-controlled proxies, exposing bearer credentials that can be used to access chat, whi...

Chrome Web Store malicious extensions coordinated campaign using shared C2

Campaign
H score38 First: 14.04.2026 23:33 Last: 14.04.2026 23:33 Sources 1

About this happening: A coordinated Chrome Web Store extension operation is stealing Google OAuth2 Bearer tokens, deploying backdoors, and running ad fraud across more than 100 malici...

108 Malicious Chrome extension campaign

Campaign
H score37 First: 14.04.2026 14:30 Last: 14.04.2026 14:30 Sources 1

About this happening: A large-scale campaign of 108 malicious Chrome extensions exposed roughly 20,000 users to session hijacking and data theft through a shared C2 infrastructure.

108 Malicious Google Chrome extensions sharing a C2 backend

Malware Activity
H score11 First: 14.04.2026 11:35 Last: 14.04.2026 11:35 Sources 1

About this happening: 108 malicious Google Chrome extensions were found to use the same C2 infrastructure to steal credentials, sessions, and browsing data while injecting ads and arbitrary Jav...

CL Suite Chrome extension stealing Meta Business data

Malware Activity
H score39 First: 13.02.2026 13:25 Last: 13.02.2026 13:25 Sources 1

About this happening: The CL Suite Chrome extension is exfiltrating TOTP seeds, current 2FA codes, and Meta Business data from Meta Business Suite and Facebook Business Manager...

Timeline

  1. 14.09.2026 10:24 2 articles · 4h ago

    Twitch Enhanced Viewer | JeetBot OAuth token leak

    Initial Disclosure

    The initial exposure began when current Twitch Enhanced Viewer | JeetBot builds forwarded Twitch OAuth tokens to operator proxy infrastructure on playlist requests. Those tokens were then logged in cleartext and exposed for every watched channel outside a small hardcoded allowlist.

    Show sources