Executive Summary
A malicious browser extension named 'Twitch Enhanced Viewer | JeetBot' has been identified exfiltrating live Twitch OAuth session tokens from approximately 31,000 users. Attributed to the Russian commercial bot service JeetBot and developer Aleksandr Alekseevich Popov, the extension targets users on both Chrome and Firefox by offering stream quality enhancements while silently capturing credentials.
The attack chain involves the extension's content script reading the Twitch Authorization header and relaying it to a background worker. Current versions (v85.x) forward these tokens as cleartext query parameters to operator-controlled proxies. Notably, the extension includes a hardcoded allowlist of ten Russian streamer channels that are exempted from token forwarding, suggesting a targeted preference for maintaining the integrity of specific accounts while exploiting others.
This exposure is critical as the exfiltrated OAuth tokens are bearer credentials, allowing attackers to bypass multi-factor authentication to read private messages, post in chat, and spend channel points. While the developer has released a patch (v85.8.7) claiming to address the issue, users must manually update the extension and reset their Twitch sessions to invalidate previously stolen tokens.
