A browser extension for the live-streaming platform Twitch, called "Twitch Enhanced Viewer | JeeBot," was discovered to be collecting users' OAuth tokens—digital keys used for authentication—and sending them to a server owned by a Russian entity. Security researchers from the firm Socket identified the extension, which is available on both Chrome and Firefox browsers. It reportedly had around 30,000 users on Chrome and 600 on Firefox. Marketed as a tool to enhance the experience for both streamers and viewers, the extension offered features like improved streaming quality, ad blocking, and an AI bot to facilitate interactions with live streams.
The researchers found that the extension used its own proxy servers to retrieve Twitch video stream playlists. However, instead of just passing along the requests, it also included users' OAuth tokens in the URL. These tokens, which are typically used to verify a user's identity, were then logged by the proxy server. This meant that anyone with access to the server logs could potentially see these tokens, which could be used to impersonate users on Twitch.
The extension’s developer, HISHIMIRO/jeetbot.cc, released an updated version (85.8.7) for Firefox (with the Chrome version still under review) that reportedly prevents the OAuth token from being sent to the proxy servers when retrieving playlists. However, according to Socket, the current versions (v85.x) still send the token as an &auth= parameter during a network redirect to the proxy server. This means the token is still exposed, albeit in a slightly different way.
Additionally, the tokens were forwarded for every channel the user watched, except for a list of ten Russian streamer channels, which were excluded from this behavior. This suggests the developer was aware of the specific channels being exempted. While the extension has been updated, users are advised to revoke any exposed Twitch tokens for safety. The researchers noted that while the actions were deliberate, it remains unclear whether the behavior was intended to be malicious.
Twitch Browser Extension Found Transmitting OAuth Tokens to Russian Server
AI-rewritten from original reportingHow it works
twitchsecurityoauthbrowser-extensionrussiajeetbot



