top of page
background.jpg

​

Cybersecurity Threat Intelligence Summary: Twitch Extension OAuth Leak

Sep 21
2 min read

A malicious cross-store browser extension named "Twitch Enhanced Viewer | JeetBot" has successfully compromised the Twitch OAuth tokens of approximately 31,000 users. Distributed via the Google Chrome Web Store (30,000 installations) and Mozilla Firefox Add-Ons store (604 installations), the tool masquerades as a quality-of-life utility that bypasses regional constraints and provides 1080p streaming. In reality, it acts as a mechanism to harvest bearer credentials for a commercial bot SaaS infrastructure.


The extension alters the routing of Twitch's video-playlist requests, redirecting them through proxy servers controlled by the operator (usher.ttvnw[.]net). During this redirection, the add-on recovers the user's active Twitch OAuth token and appends it in cleartext as an &auth= query parameter within the URL. This design flaw or intentional mechanism ensures that the credential is written directly into the proxy server's request logs. Previous versions of the extension (v4.x) were even more direct, actively POSTing the tokens to dedicated endpoints on the operator's host and backup domains like deno.dev.


The leaked OAuth token is a bearer credential, meaning possession of the token grants the attacker authenticated access to the user's account without requiring the underlying password or passing Multi-Factor Authentication (MFA) challenges. Threat actors holding these tokens can read private messages (whispers), post in live chats, spend accumulated channel points, and alter account settings.


Security researchers at Socket discovered that the exfiltration routine is disabled for a hardcoded allowlist of 10 specific Twitch channels, predominantly consisting of high-profile Russian-language streamers (e.g., akyuliych, pch3lk1n, and fasoollka). The extension is tied to "HISHIMIRO/jeetbot.cc", operated by a Cyprus-based developer named Aleksandr Popov. JeetBot itself is marketed as a commercial botting service for Twitch, Kick, and VK Live, claiming over 26,000 active streamers.

Following the exposure of this mechanism, the developer published an update (version 85.8.7 for Firefox, with Chrome pending review) that ceases the transmission of the token. However, updating or disabling the extension does not automatically revoke the previously exfiltrated tokens, leaving historical victims at risk until they manually invalidate their Twitch sessions.


Key Precautions Users Should Take:


  • Revoke OAuth Tokens and Active Sessions

  • Remove or Update the Extension

  • Audit Account Activity

  • Restrict Over-Privileged Extensions


For detailed information, you can reach out to our experts at info@zerosecond.com.ae .

 
 
 

Comments


bottom of page