JeetBot Twitch Extension Steals OAuth Tokens
Score: 8/10

JeetBot Twitch Extension Steals OAuth Tokens

The JeetBot browser extension exfiltrates Twitch OAuth tokens to Russian proxy infrastructure, affecting over 31,000 users.

Executive Summary

A malicious browser extension named 'Twitch Enhanced Viewer | JeetBot' has been identified exfiltrating live Twitch OAuth session tokens from approximately 31,000 users. Attributed to the Russian commercial bot service JeetBot and developer Aleksandr Alekseevich Popov, the extension targets users on both Chrome and Firefox by offering stream quality enhancements while silently capturing credentials.

The attack chain involves the extension's content script reading the Twitch Authorization header and relaying it to a background worker. Current versions (v85.x) forward these tokens as cleartext query parameters to operator-controlled proxies. Notably, the extension includes a hardcoded allowlist of ten Russian streamer channels that are exempted from token forwarding, suggesting a targeted preference for maintaining the integrity of specific accounts while exploiting others.

This exposure is critical as the exfiltrated OAuth tokens are bearer credentials, allowing attackers to bypass multi-factor authentication to read private messages, post in chat, and spend channel points. While the developer has released a patch (v85.8.7) claiming to address the issue, users must manually update the extension and reset their Twitch sessions to invalidate previously stolen tokens.

Key Details

Threat Name

JeetBot Twitch extension

Affects

—

Adversary

JeetBot

Malware/Tools

JeetBot, Twitch Enhanced Viewer | JeetBot

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance6
Enterprise Relevance5
Clarity & Structure9
Technical Depth9

Sources