Twitch Enhanced Viewer | JeetBot OAuth token-stealing extension
Malware Activity
Summary
Hide ▲
Show ▼
Twitch Enhanced Viewer | JeetBot is leaking Twitch OAuth tokens through operator-controlled proxies, exposing bearer credentials that can be used to access chat, whispers, account settings, and channel points. The current v85.x builds forward tokens with an `&auth=` parameter during Twitch playlist requests, and earlier v4.x builds also posted tokens to a dedicated operator endpoint. The extension is listed across Chrome and Firefox stores and is associated with nearly 31,000 users. A documented update to 85.8.7 stops the token forwarding, but older installs continue to transmit credentials until they are changed.
Related Happenings
Twitch Enhanced Viewer | JeetBot OAuth token leak
Data Leak
H score36
First: 14.09.2026 10:24
Last: 14.09.2026 10:24
Sources 1
How related:
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.
About this happening:
A malicious Twitch browser extension exposed OAuth bearer tokens for nearly 31,000 users, creating account-takeover risk across chat, whispers, account settings, and c...
Twitch Enhanced Viewer | JeetBot OAuth token leak
Data LeakHow related: A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.
About this happening: A malicious Twitch browser extension exposed OAuth bearer tokens for nearly 31,000 users, creating account-takeover risk across chat, whispers, account settings, and c...
Malicious Chrome and Edge browser-extension campaign
Campaign
H score16
First: 30.08.2026 17:17
Last: 30.08.2026 17:17
Sources 1
About this happening:
A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...
Malicious Chrome and Edge browser-extension campaign
CampaignAbout this happening: A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...
Superior malicious extension installation campaign
Campaign
H score17
First: 28.08.2026 18:27
Last: 28.08.2026 18:27
Sources 1
About this happening:
The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...
Superior malicious extension installation campaign
CampaignAbout this happening: The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...
Malicious VPN and proxy extension campaign targeting Russian-speaking users
Campaign
H score41
First: 12.08.2026 17:09
Last: 12.08.2026 17:09
Sources 1
About this happening:
A 737-extension campaign is intercepting browser traffic for Russian-speaking users by routing sessions through SOCKS5 proxy infrastructure, exposing destinations,...
Malicious VPN and proxy extension campaign targeting Russian-speaking users
CampaignAbout this happening: A 737-extension campaign is intercepting browser traffic for Russian-speaking users by routing sessions through SOCKS5 proxy infrastructure, exposing destinations,...
Chrome Web Store malicious extensions coordinated campaign using shared C2
Campaign
H score38
First: 14.04.2026 23:33
Last: 14.04.2026 23:33
Sources 1
About this happening:
A coordinated Chrome Web Store extension operation is stealing Google OAuth2 Bearer tokens, deploying backdoors, and running ad fraud across more than 100 malici...
Chrome Web Store malicious extensions coordinated campaign using shared C2
CampaignAbout this happening: A coordinated Chrome Web Store extension operation is stealing Google OAuth2 Bearer tokens, deploying backdoors, and running ad fraud across more than 100 malici...
Timeline
-
14.09.2026 10:24 1 articles · 4h ago
Twitch Enhanced Viewer | JeetBot appears on the Chrome Web Store
Campaign Scope UpdateThe malicious Twitch extension "Twitch Enhanced Viewer | JeetBot" is published on the Chrome Web Store under HISHIMIRO/jeetbot.cc, with the listing showing 30,000 users.
Show sources
- Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users — thehackernews.com — 14.09.2026 10:24
-
14.09.2026 10:24 1 articles · 4h ago
Twitch Enhanced Viewer | JeetBot appears on Mozilla Firefox Add-Ons
Campaign Scope UpdateThe same Twitch extension is published on Mozilla Firefox Add-Ons as [email protected], with the listing showing 604 users.
Show sources
- Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users — thehackernews.com — 14.09.2026 10:24
-
14.09.2026 10:24 2 articles · 4h ago
JeetBot leaks Twitch OAuth tokens through operator-controlled proxies
Initial DisclosureSocket reports that current v85.x builds of Twitch Enhanced Viewer | JeetBot forward Twitch OAuth tokens inline as an &auth= query parameter on a network-layer redirect to the operator's proxy, exposing bearer credentials that can be used for chat, whispers, account settings, and channel points. The reporting also says earlier v4.x builds such as version 4.8 in January 2026 POSTed the token to a dedicated set-token endpoint on the operator host, with backups on deno.dev and deno.net. The JeetBot documentation says version 85.8.7 of the Firefox add-on stops sending the token to the proxies, an equivalent Chrome version is under review, and previously transmitted tokens are not revoked automatically.
Show sources
- Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users — thehackernews.com — 14.09.2026 10:24
- Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users — thehackernews.com — 14.09.2026 10:24