Malicious Twitch Browser Extension Steals 31,000 Users' Account Tokens
Security researchers at Socket have found that a browser extension called Twitch Enhanced Viewer | JeetBot, available on both the Chrome Web Store and Firefox Add-ons, has been quietly forwarding users' Twitch account tokens to proxy servers linked to a Russian commercial bot service. The extension, which promises perks like ad blocking, forced 1080p video and region unlocking, routes video requests through these proxy servers, and in doing so leaks the user's account token in plain text within the request logs.
This token is a bearer credential, meaning anyone who obtains it can access the victim's Twitch account, including sending messages, posting in chat and spending channel points, without needing a password or two-factor authentication. Researchers noted the extension does not need this token to function normally, which suggests the data collection may be intentional rather than accidental. Earlier versions of the extension reportedly sent captured tokens directly to dedicated servers controlled by the bot service, complete with backup systems and code comments written in Russian instructing the tool to fail silently if a transfer did not succeed.
At the time of the research's publication, the extension listings remained live on both browser stores. This case highlights the ongoing risk posed by third-party browser extensions that request excessive permissions or account access beyond what their advertised features require.