Twitch Extension with 30K Installs Exposes Users' OAuth Tokens
A browser extension named JeetBot, available in official stores, was found silently exfiltrating Twitch OAuth session tokens to a commercial bot service.

A popular browser extension called Twitch Enhanced Viewer | JeetBot, which was available on the official Chrome and Firefox web stores, has been caught exposing user data. According to BleepingComputer, the extension transmits users' Twitch OAuth session tokens to a commercial bot service without their knowledge.
At the time of the discovery, the extension had accumulated over 30,000 installs. This security flaw poses a significant threat, as leaked OAuth tokens can grant unauthorized third-party access to the victims' Twitch accounts, potentially compromising personal information and interaction capabilities.
The incident highlights ongoing security concerns surrounding third-party browser extensions. Many users routinely install productivity or streaming tools without realizing the risks associated with excessive permissions and hidden background data transfers.
For tech-savvy audiences and content creators in developing markets, including Central Asia and CIS regions, this serves as a critical reminder regarding digital hygiene. Trusting unverified browser extensions can easily lead to severe account takeovers.
Cybersecurity experts strongly advise users who have installed the JeetBot extension to remove it immediately, revoke active sessions, and reset their Twitch account credentials to prevent any potential unauthorized access.



