JeetBot content.js captures Twitch OAuth header via tev-proxy-session
Detects anomalous execution or network activity involving a 'content.js' file in conjunction with specific proxy-related artifacts or authorization headers. This pattern is indicative of a malicious browser extension or script attempting to intercept or proxy web traffic and credentials.
Microsoft Sentinel (KQL)

