Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Twitch Browser Extension Breach: A Comprehensive Examination of the OAuth Token Leaks and the Implications for User Security




A malicious Twitch browser extension has leaked OAuth tokens from nearly 31,000 users, compromising their Twitch accounts and sensitive information. The extension, titled "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has been available on the Google Chrome Web Store and Mozilla Firefox Add-Ons store. The breach, which occurred due to poor design choices and inadequate testing, has significant implications for user security. The incident highlights the need for greater transparency and accountability in the app review process, as well as the importance of user education and awareness regarding online security.

  • Nearly 31,000 Twitch users fell victim to a malicious browser extension that leaked OAuth tokens to proxy servers operated by a Russian bot service.
  • The extension's poor design and inadequate testing allowed the malicious operator to access sensitive user data, including chat, whispers, and account settings.
  • The incident highlights the laxity of oversight in the app review process, with the extension available on both Google Chrome Web Store and Mozilla Firefox Add-Ons store.
  • The breach underscores the importance of robust security measures in protecting user data and the need for greater transparency and accountability in the app review process.
  • It also highlights the need for user education and awareness regarding online security, as the malicious operator exploited a combination of poor design choices and inadequate testing.



  • The Twitch browser extension debacle has shed light on the precarious nature of online security, with nearly 31,000 users falling prey to a malicious cross-store Twitch browser extension that leaked OAuth tokens to proxy servers operated by a Russian commercial bot service. The extension, titled "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer, and its availability on both the Google Chrome Web Store and Mozilla Firefox Add-Ons store is a testament to the laxity of oversight in the app review process.

    According to Socket security researcher Kush Pandya, the extension's implementation forwarded the user's Twitch OAuth token as an &auth= query parameter on a network-layer redirect to the operator's proxy, a mechanism that is not only insecure but also raises significant concerns regarding the handling of sensitive user data. The token, which is a credential and must be protected, was forwarded for every channel the user watched, except for a hardcoded list of ten Russian streamer channels, whose sessions were exempted from forwarding.

    The breach, which occurred due to a combination of poor design choices and inadequate testing, had significant implications for the affected users. The exposed OAuth tokens not only compromised the users' Twitch accounts but also enabled the malicious operator to access other sensitive information, including the users' chat, whispers, and account settings. The operator, who is based in Cyprus and claims to be a Cyprus-based developer named Aleksandr Popov, initially downplayed the severity of the breach, stating that it was an oversight that had been addressed in the latest version of the extensions.

    However, upon further examination, it becomes apparent that the breach was not merely an isolated incident, but rather a symptom of a larger issue. The Twitch Enhanced Viewer | JeetBot extension, which is one of many Twitch playback extensions available on the Chrome Web Store and Mozilla Firefox Add-Ons store, explicitly mentions in its listing that it transmits the user's Twitch OAuth token to its server to provide "1080p/1440p quality access" for Russian users. This revelation highlights the laxity of oversight in the app review process and raises questions regarding the handling of sensitive user data.

    The breach also raises concerns regarding the broader implications of OAuth token leaks. The exposed tokens, which can be used to access sensitive information, have significant implications for user security. The fact that the malicious operator was able to access the users' Twitch accounts, as well as other sensitive information, underscores the importance of robust security measures in protecting user data.

    Furthermore, the breach highlights the need for greater transparency and accountability in the app review process. The fact that the developer, Aleksandr Popov, initially downplayed the severity of the breach, only to later acknowledge that it was an oversight, raises questions regarding the effectiveness of the review process. The need for greater transparency and accountability in the app review process is crucial in preventing similar breaches in the future.

    In light of the breach, it is essential to emphasize the importance of robust security measures in protecting user data. The fact that nearly 31,000 users fell prey to the malicious cross-store Twitch browser extension highlights the need for greater vigilance in protecting user security. The incident serves as a stark reminder of the importance of robust security measures and the need for greater transparency and accountability in the app review process.

    The breach also underscores the importance of user education and awareness. The fact that the malicious operator was able to exploit the OAuth token leaks due to a combination of poor design choices and inadequate testing highlights the need for greater awareness and education regarding online security. The incident serves as a stark reminder of the importance of robust security measures and the need for greater vigilance in protecting user security.

    In conclusion, the Twitch browser extension breach is a stark reminder of the importance of robust security measures in protecting user data. The incident highlights the need for greater transparency and accountability in the app review process, as well as the importance of user education and awareness. The breach serves as a warning to users to be vigilant and to prioritize their online security, and it underscores the need for greater vigilance in protecting user data.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Twitch-Browser-Extension-Breach-A-Comprehensive-Examination-of-the-OAuth-Token-Leaks-and-the-Implications-for-User-Security-ehn.shtml

  • https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html


  • Published: Thu Sep 17 13:13:17 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us