Follow
Subscribe via Email!

Enter your email address to subscribe to this platform and receive notifications of new posts by email.

31,000 Users Hit as Twitch Extension Exposes Account Tokens

A security audit revealed that the Twitch extension JeetBot leaked OAuth session tokens from nearly 31,000 users to external proxies, prompting emergency updates.
TechRadar graphic illustrating the Twitch extension security vulnerability and exposed session credentials.

A browser add-on installed across tens of thousands of computers quietly siphoned live session credentials into external server logs. The risk was immediate. Cybersecurity researchers at Socket revealed on September 14 that the Twitch extension “Twitch Enhanced Viewer | JeetBot” captured account authorization tokens from roughly 31,000 viewers. JeetBot forwarded these OAuth tokens (digital keys authorizing account access without passwords) directly to proxy servers operated by a commercial bot service. Security analysts confirmed that the credential exposure left user chats, private whispers, and platform account settings vulnerable across both Google Chrome and Mozilla Firefox web browsers. [1, 2, 3, 4]

Twitch Extension Captures Session Tokens

Promoted as an all-in-one viewer companion, the Twitch Enhanced Viewer promised high-definition streaming and automated conveniences. Official listings in Google Chrome and the Chrome Web Store alongside the Mozilla Firefox store marketed the program to broadcasters and viewers seeking improved playback performance. Promotional materials highlighted ad blocking, forced 1080p and 2K resolution playback, channel-point collection, and bypasses for regional broadcast limits. In Google Chrome, the software operated under identifier pnhhdhhcadcjfckjhpmjneldiegbojfb, accumulating 30,000 installs since June 26, 2025. Mozilla Firefox logged 604 downloads under twitchenhancedviewer@example.com following its July 7, 2025 debut. Store listings remained online. [2, 3, 6]

Behind those advertised perks lay an undocumented credential pipeline. Socket researcher Kush Pandya discovered that the Twitch Enhanced Viewer extension intercepted the authorization header used by the Twitch web client whenever a viewer loaded a broadcast. The software extracted the active session token and transmitted the bearer credential to remote infrastructure managed by JeetBot, a commercial SaaS platform providing automated chatbots and streaming tools for Twitch, Kick, and VK Live. Because an OAuth session token functions as a digital passkey, anyone possessing it can perform account actions without entering a password or satisfying two-factor authentication checks on Twitch. No second factor was prompted. [2, 3, 4]

What operational latitude did that token grant an unauthorized holder? Kush Pandya and Socket warned that the compromised credentials enabled extensive administrative actions across Twitch accounts. Possessors could send whispers (private direct messages), post chat messages, modify account settings, and spend accumulated channel points. The Twitch Enhanced Viewer extension requested broad host permissions on Twitch, allowing it to relay live authenticated sessions through private proxy infrastructure without any warning displayed in official Chrome Web Store listings. [2, 3, 5]

Twitch extension security investigation featured in BleepingComputer coverage.
BleepingComputer reported on how third-party browser add-ons can expose active user credentials. (Credit: BleepingComputer)

Cleartext Logging and Proxy Redirects

Security analysts revealed that the platform token leakage stemmed directly from how the Twitch Enhanced Viewer extension handled live stream playlist retrieval requests across third-party networks. When a user started watching a stream, Twitch sent a video playlist query directed to the host usher.ttvnw[.]net. Rather than allowing the web browser to query Twitch servers directly, the add-on redirected that network-layer video request through remote Russian-owned proxy servers operated by JeetBot. During that redirection, the software appended the user’s live OAuth token directly to the URL address as an inline &auth= query parameter. Logging occurred automatically. [1, 3, 6]

Embedding authentication credentials directly inside a web address violates standard network security practices. Because query strings are processed as standard URL parameters, proxy servers routinely record complete destination web addresses in administrative access logs. Socket researcher Kush Pandya confirmed that JeetBot proxy infrastructure wrote every forwarded token into plain server logs in cleartext, where commercial server operators could view and retrieve the sensitive credentials at will. The data flow contradicted public assurances. While developer disclosures on the Chrome Web Store claimed the software did not collect or transfer user data outside approved functions, live network traffic routed private session credentials straight into external proxy storage. [2, 3, 4]

Earlier iterations of the Twitch Enhanced Viewer extension relied on even more aggressive credential collection techniques. Socket researcher Kush Pandya revealed that version 4.x releases dating back to January 2026 did not bother disguising transmissions inside playlist redirects. Instead, builds such as version 4.8 transmitted tokens through dedicated POST requests to an operator host endpoint, with secondary backup destinations maintained on deno.dev and deno.net. Across successive iterations, the software continued routing sensitive tokens off the local machine. Backup hosts remained available. [3]

Ten Channels Excluded From Forwarding

Security researchers uncovered an anomaly in the extension redirect code that pointed toward intentional filtering. Current builds forwarded session credentials for nearly every channel on the platform, yet Socket researcher Kush Pandya identified a hardcoded list of ten Russian-language streamer channels that never triggered token forwarding. When a viewer tuned into any of those ten broadcasts, the Twitch Enhanced Viewer extension bypassed proxy redirection entirely. Sessions on those specific channels remained local, leaving the viewer’s authorization header untouched while all other streams transmitted credentials externally. [1, 3, 5]

Ten channels enjoyed complete immunity. While thirty thousand users surrendered credentials across thousands of global broadcasts, that hardcoded allowlist never leaked a single token. [1, 3]

Twitch extension analysis and branding featured in The Hacker News reporting.
The Hacker News detailed the transmission of session credentials through external proxy servers. (Credit: The Hacker News)

The exempted list comprised prominent Russian-language Twitch personalities representing millions of collective community subscribers across competitive esports and gaming broadcasts. The channels included akyuliych with 1.1M followers, pch3lk1n with 580K followers, fasoollka with 361K followers, lagoda1337 with 225K followers, forzorezor with 177K followers, flamie with 132K followers, and lagoda with 77.3K followers. Smaller channels also appeared on the allowlist, including dosia with 29 followers, almazer with 4 followers, and fander with 2 followers. The existence of specific exemptions convinced researchers that the routing logic was deliberately configured rather than accidental. For every stream outside that select roster, live credentials traveled straight to the operator’s proxy servers. [1, 3, 5]

Developer Cites Oversight in Playback Code

JeetBot operator Aleksandr Popov defended the Twitch Enhanced Viewer architecture while acknowledging significant procedural oversights. Speaking to The Hacker News, Cyprus developer Aleksandr Popov insisted the project was a personal endeavor rather than a malicious utility. Popov explained that JeetBot serves over 26,000 streamers and has processed more than 1 billion messages across Twitch, Kick, and VK Live. He maintained that forwarded tokens supported video playback features and were never utilized for unauthorized account takeovers or automated messaging. Popov denied malicious intent. [3]

Why were those ten Russian-language channels excluded from forwarding? Aleksandr Popov explained that exemptions originated from technical workarounds for geographical stream errors. Viewers accessing Russian streams from abroad or through virtual private networks frequently encountered Error #3, an error message indicating that Twitch had detected an unauthorized proxy or unblocker. According to Aleksandr Popov, developers introduced an alternative playback path that bypassed token forwarding to resolve the error. He stated that the list became user-configurable in version 85.8.4 under a setting labeled “Channels with restrictions,” where viewers could manually add or remove channels based on local connection problems. [3]

Cyber Security News graphic analyzing the Twitch extension token vulnerability.
Cyber Security News published technical indicators of compromise associated with the proxy servers. (Credit: Cyber Security News)

Aleksandr Popov assigned day-to-day development of the add-on to a developer named Hishimiro, conceding that review procedures broke down. Aleksandr Popov noted that competing Russian playback utilities, including ReYohoho Twitch Proxy, XT Viewer, and ggsel Ханти, also transmit tokens to achieve 1080p and 1440p playback, though those tools disclose the practice in store summaries. Credential mismanagement remains a recurring threat across consumer software ecosystems, as documented in earlier security investigations analyzing app secrets exposed across 1.8 million Android applications. Popov confirmed that his team accepted responsibility for failing to disclose credential transmissions. [2, 3]

How to Remove Twitch Extensions Safely

The developer released an update. Version 85.8.7 of the Mozilla Firefox add-on modified stream playlist handling to stop routing session credentials through proxy systems. Aleksandr Popov submitted a matching update for Google Chrome, which remained under review in the Chrome Web Store. A warning published in JeetBot technical documentation urged viewers to verify their installed version and advised anyone running older builds to disable the add-on immediately. Google Chrome and Chrome Web Store review remained pending. [1, 3, 4]

However, updating or removing the browser add-on does not neutralize tokens that have already leaked. Because a Twitch session token remains valid until explicitly invalidated, security analysts emphasized that active bearer tokens sitting in proxy logs remain dangerous. To eliminate the risk, affected viewers must open their Twitch account settings, navigate to active connections and security sessions, and disconnect all logged-in devices. Logging out forces Twitch to revoke previous authorization tokens before users re-authenticate with fresh credentials. [1, 2, 4]

For viewers researching Twitch extensions and browser security, the incident reinforces strict precautions when handling third-party streaming utilities. BleepingComputer writer Bill Toulas reported that users can inspect active extensions in Google Chrome via chrome://extensions or in Mozilla Firefox via about:addons. Reporter Bill Toulas and The Hacker News detailed how third-party convenience tools should never require surrendering fundamental account credentials. Security researchers advised developers never to route authenticated headers through third-party intermediaries, reminding broadcasters that account safety outweighs convenience. [1, 2, 5, 6]

Sources
  1. ONLINE NEWS Fadilpašić, S. (2026, September 14). 31,000 Twitch users hit by malicious browser extension — OAuth tokens leaked via Russian proxy network. TechRadar. [Article Link]
  2. ONLINE NEWS Toulas, B. (2026, September 14). Twitch extension with 30K installs exposes users’ OAuth tokens. BleepingComputer. [Article Link]
  3. ONLINE NEWS The Hacker News. (2026, September 14). Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users. The Hacker News. [Article Link]
  4. ONLINE NEWS Dutta, T. S. (2026, September 14). Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users. Cyber Security News. [Article Link]
  5. ONLINE NEWS Mascellino, A. (2026, September 14). Malicious Twitch Extension Exposes 31,000 Users’ OAuth Tokens. Infosecurity Magazine. [Article Link]
  6. ONLINE NEWS Mann, B. (2026, September 14). Malicious Twitch extension exposed OAuth tokens of 30,000 users. CyberInsider. [Article Link]

Leave a Comment

Related Posts
Total
0
Share