Browser extension combining Twitch auth-domain permissions with proxy C2
Detects the installation or update of a browser extension that requests specific host permissions related to Twitch (gql.twitch.tv, usher.ttvnw.net, id.twitch.tv) combined with suspicious domains (jeetbot.cc, drisnya.online, morphilina.me, deno.dev, deno.net). This pattern is indicative of malicious browser extensions designed to intercept credentials or manipulate Twitch-related traffic.
Microsoft Sentinel (KQL)

