31,000 Twitch users hit by malicious browser extension — OAuth tokens leaked via Russian proxy network
Over 31,000 Twitch users unwittingly exposed their OAuth tokens when a popular browser add‑on routed video playlists through a Russian‑owned proxy, embedding the token in the request URL. The leak compromises account control, stream‑chat identity, and any third‑party services linked to the token. Understanding the mechanics lets viewers and streamers protect their digital presence before the damage spreads.
Extension Architecture and Token Leakage Mechanism
The add‑on, marketed as “Twitch Enhanced Viewer | JeeBot,” claims to improve video quality, hide ads, and provide an AI chat helper. In reality, it intercepts Twitch’s playlist requests and forwards them to the developer’s proxy network, inserting the user’s OAuth token as an &auth= query parameter on each redirect. Because the token appears in the URL, the proxy’s server logs capture it in plain text, making it trivially harvestable.
Socket’s analysis recorded roughly 30,000 Chrome installations and about 600 Firefox users, indicating a sizable attack surface across two major browsers. The extension’s code hard‑codes the proxy endpoint, leaving no user‑configurable option to bypass it, which means every viewer who installs the add‑on automatically consents to token exposure. This design choice eliminates any meaningful consent flow and sidesteps browser security warnings that normally flag URL‑based credential leakage.
From a technical standpoint, the token leakage exploits the fact that OAuth tokens for Twitch are often passed as URL parameters for convenience in API calls. When the extension rewrites the request, it does not strip or encrypt the token, violating the principle of least privilege. The result is a systematic exfiltration channel that operates at the network layer, invisible to the user’s browser console or typical extension permission dialogs.
Hardcoded Exemptions and Intentional Targeting
Socket discovered that the extension deliberately omitted token forwarding for only ten Russian streamer channels, a pattern that suggests selective design rather than accidental oversight. The exemption list is embedded in the source code, meaning the developer explicitly chose which accounts to protect, likely to avoid drawing attention from local authorities or to preserve a foothold in a specific community.
This selective shielding raises the possibility that the proxy network was intended to harvest tokens from the broader, non‑Russian audience while preserving access for a small, perhaps politically aligned group. The fact that the exemption is limited to “Russian streamer channels” aligns with the proxy’s ownership, hinting at a geopolitical motive intertwined with commercial data collection.
Such targeted behavior complicates the threat model: the extension is not merely a sloppy developer mistake but a purposeful data‑gathering tool that differentiates users based on geography. For security analysts, this pattern signals a need to scrutinize other extensions that claim regional exemptions, as they may conceal similar covert data pipelines.
Response, Patch, and Residual Risks
After the vulnerability was disclosed, the developer (identified as HISHIMIRO/jeetbot.cc) issued version 85.8.7 for Firefox and submitted a Chrome update that removes the token from the proxy request. The patch replaces the inline &auth= parameter with a server‑side token exchange that does not expose credentials in URLs. This rapid response suggests the issue could have been an implementation error rather than a pre‑planned espionage vector.
However, the damage may already be irreversible for users who installed earlier versions. OAuth tokens can be reused until revoked, granting attackers persistent access to a user’s Twitch account, including the ability to stream, modify channel settings, or post chat messages. The sheer number of affected users means that token‑replay attacks could be automated at scale.
Furthermore, the Chrome version remains under review, leaving a window where new installs might still inherit the vulnerable code. Even with the patch, browsers cache extensions, and some users may never receive the update if they have auto‑update disabled. Consequently, the risk profile persists beyond the initial fix, demanding proactive user action.
What This Actually Means For You
- Every Twitch account that used the JeeBot extension before the patch has an exposed OAuth token that could be used to hijack the account.
- Revoking the token from Twitch’s developer console instantly invalidates any stolen credentials, cutting off unauthorized access.
- Future installations of browser extensions that manipulate network traffic should be vetted for hidden proxy endpoints and URL‑based token handling.
- Even after revocation, attackers could have already linked the token to other services (e.g., third‑party bots), so monitoring account activity is essential.
Immediate Action Steps
Log into your Twitch account, navigate to the “Authorized Applications” section, and revoke the token associated with the JeeBot extension; this forces a fresh token generation the next time you log in. Then, remove the extension from both Chrome and Firefox, and clear your browser cache to eliminate any lingering proxy configuration.
If you continue to need enhanced viewing features, seek alternatives that explicitly state they do not transmit OAuth credentials in URLs and that have undergone independent security audits. Until such tools are verified, stick to Twitch’s native player settings to avoid inadvertent data leakage.
Frequently Asked Questions
Did the JeeBot extension intentionally steal Twitch OAuth tokens?
Socket’s research shows the extension forwarded tokens as an &auth= query parameter to a Russian‑owned proxy for every channel except ten Russian streamers, indicating a deliberate design choice rather than an accidental bug.
How can I tell if my Twitch token was compromised?
Check the “Authorized Applications” page on Twitch; if you see an entry for JeeBot or notice unfamiliar activity such as unexpected chat messages or stream changes, the token was likely harvested and should be revoked immediately.
Is the new version of the extension safe to use?
The developer released version 85.8.7 that stops sending the token in URLs, but the Chrome update is still under review, and existing installations may remain vulnerable if auto‑update is disabled.
What Do You Think?
Given the selective exemption for Russian channels, do you believe the extension’s original intent was malicious data collection or a careless implementation that was quickly weaponized?