Find notable cyber news and cases, enriched with sources, timelines, and signals.

Twitch Enhanced Viewer | JeetBot OAuth token-stealing extension

Malware Activity
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

Twitch Enhanced Viewer | JeetBot is leaking Twitch OAuth tokens through operator-controlled proxies, exposing bearer credentials that can be used to access chat, whispers, account settings, and channel points. The current v85.x builds forward tokens with an `&auth=` parameter during Twitch playlist requests, and earlier v4.x builds also posted tokens to a dedicated operator endpoint. The extension is listed across Chrome and Firefox stores and is associated with nearly 31,000 users. A documented update to 85.8.7 stops the token forwarding, but older installs continue to transmit credentials until they are changed.

Related Happenings

Twitch Enhanced Viewer | JeetBot OAuth token leak

Data Leak
H score36 First: 14.09.2026 10:24 Last: 14.09.2026 10:24 Sources 1

How related: A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.

About this happening: A malicious Twitch browser extension exposed OAuth bearer tokens for nearly 31,000 users, creating account-takeover risk across chat, whispers, account settings, and c...

Malicious Chrome and Edge browser-extension campaign

Campaign
H score16 First: 30.08.2026 17:17 Last: 30.08.2026 17:17 Sources 1

About this happening: A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...

Superior malicious extension installation campaign

Campaign
H score17 First: 28.08.2026 18:27 Last: 28.08.2026 18:27 Sources 1

About this happening: The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...

Malicious VPN and proxy extension campaign targeting Russian-speaking users

Campaign
H score41 First: 12.08.2026 17:09 Last: 12.08.2026 17:09 Sources 1

About this happening: A 737-extension campaign is intercepting browser traffic for Russian-speaking users by routing sessions through SOCKS5 proxy infrastructure, exposing destinations,...

Chrome Web Store malicious extensions coordinated campaign using shared C2

Campaign
H score38 First: 14.04.2026 23:33 Last: 14.04.2026 23:33 Sources 1

About this happening: A coordinated Chrome Web Store extension operation is stealing Google OAuth2 Bearer tokens, deploying backdoors, and running ad fraud across more than 100 malici...

Timeline

  1. 14.09.2026 10:24 2 articles · 4h ago

    JeetBot leaks Twitch OAuth tokens through operator-controlled proxies

    Initial Disclosure

    Socket reports that current v85.x builds of Twitch Enhanced Viewer | JeetBot forward Twitch OAuth tokens inline as an &auth= query parameter on a network-layer redirect to the operator's proxy, exposing bearer credentials that can be used for chat, whispers, account settings, and channel points. The reporting also says earlier v4.x builds such as version 4.8 in January 2026 POSTed the token to a dedicated set-token endpoint on the operator host, with backups on deno.dev and deno.net. The JeetBot documentation says version 85.8.7 of the Firefox add-on stops sending the token to the proxies, an equivalent Chrome version is under review, and previously transmitted tokens are not revoked automatically.

    Show sources