Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Malicious JeetBot Twitch Browser Extension Exposes OAuth Tokens of Nearly 31,000 Users




A malicious Twitch browser extension, JeetBot, has exposed the OAuth tokens of nearly 31,000 users, putting them at risk of identity theft and other malicious activities. The extension, which was published on the Google Chrome Web Store and Mozilla Firefox Add-Ons store, has been leaking OAuth tokens to proxy servers operated by a Russian commercial bot service. The incident highlights the importance of browser security and the need for users to exercise vigilance when using online applications.

  • JeetBot browser extension leaked OAuth tokens of nearly 31,000 Twitch users to Russian commercial bot service.
  • The extension was designed to leak OAuth tokens to proxy servers for every channel the user watches, except for a hardcoded list of ten Russian-language streamers.
  • The malicious activities of the extension were made possible by the use of a proxy server operated by a Russian commercial bot service.
  • The developer of the JeetBot extension attempted to address the issue by releasing a new version, but users are advised to temporarily disable the extension to halt further transmission of the token.
  • The incident highlights the importance of browser security and the need for users to exercise vigilance when using online applications.



  • The online security landscape has been recently shaken by the revelation of a malicious Twitch browser extension, JeetBot, that has been leaking OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. This alarming incident highlights the importance of browser security and the need for users to exercise vigilance when using online applications.

    The JeetBot browser extension, which was published on the Google Chrome Web Store and Mozilla Firefox Add-Ons store, has been identified as a cross-store extension, meaning it is available for download on multiple platforms. The extension's developer, Aleksandr Popov, has been identified as a Cyprus-based developer. However, the true extent of Popov's involvement in the malicious activities of the extension remains unclear.

    According to Socket security researcher Kush Pandya, the JeetBot extension uses an OAuth token to authenticate users' Twitch accounts. This token is a crucial piece of information that allows users to access their account settings, send private messages, and engage in other online activities. However, the extension's design allows it to leak this token to proxy servers operated by a Russian commercial bot service, putting nearly 31,000 users at risk of identity theft and other malicious activities.

    The JeetBot extension's design is particularly concerning because it allows the token to be forwarded to proxy servers for every channel the user watches, except for a hardcoded list of ten Russian-language streamers. This means that users who are watching these channels are not immune to the malicious activities of the extension.

    The malicious activities of the JeetBot extension are made possible by the use of a proxy server, which is a server that acts as an intermediary between a user's device and the internet. In this case, the proxy server is operated by a Russian commercial bot service that has broad Twitch host permissions and relays live authenticated sessions through its own infrastructure. This means that the JeetBot extension can access users' Twitch accounts and engage in malicious activities without being detected.

    The JeetBot extension's design also includes a mechanism to recover the Twitch OAuth token and send it to the proxy server, which can be written in cleartext into the proxy server's request logs. This means that the token can be intercepted by malicious actors and used to access users' Twitch accounts.

    The developer of the JeetBot extension, Aleksandr Popov, has attempted to address the issue by releasing a new version of the extension, version 85.8.7, which changes how playlists are retrieved and no longer sends the user's OAuth token to the proxy servers. However, this change does not revoke previously transmitted tokens, and users are advised to temporarily disable the extension to halt further transmission of the token if the extension is not available.

    The revelation of the JeetBot extension's malicious activities has sparked concerns among online security experts and users. The incident highlights the importance of browser security and the need for users to exercise vigilance when using online applications. It also underscores the need for developers to design browser extensions that prioritize user security and privacy.

    In conclusion, the malicious JeetBot Twitch browser extension has exposed the OAuth tokens of nearly 31,000 users, putting them at risk of identity theft and other malicious activities. The incident highlights the importance of browser security and the need for users to exercise vigilance when using online applications.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Malicious-JeetBot-Twitch-Browser-Extension-Exposes-OAuth-Tokens-of-Nearly-31000-Users-ehn.shtml

  • https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html


  • Published: Mon Sep 14 03:49:13 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us