×
×

Twitch Extension Leak OAuth Token, 30,000 Chrome Users Affected

Researchers from Socket find say one Twitch browser extension wey about 30,000 Chrome users dey use don dey transmit OAuth authentication tokens go infrastructure wey its developer control. The extension name na Twitch Enhanced Viewer | JeetBot. E dey official Chrome and Firefox stores. E advertise features like higher-quality playback, ad blocking, and automatic channel-point collection.

Socket talk say the extension fit extract OAuth tokens from authenticated Twitch sessions and attach them to requests wey e send through proxy servers wey developer control. That one fit give receiving infrastructure capabilities tied to users accounts. According to Socket, extension dey run as intended and still live for both stores as of publication.

At first glance, neither extension look like fresh or suspicious upload. According to The Hacker News, Chrome version don dey available since June 26, 2025, while Firefox version was published on July 7, 2025. Chrome listing get about 30,000 users, while Firefox version get 552. That make the add-ons appear like established Twitch tools, not newly published extensions.

The extensions route playlist requests through JeetBot-controlled proxy servers to provide features such as 1080p playback in restricted regions. The extension fit access Twitch data inside browser, recover the OAuth token associated with user already-authenticated Twitch session, then attach that token to requests sent through proxy. The security concern na the difference between access wey extension advertised features require and credentials wey e actually transmit.

According to Socket, having that token fit allow read and write access to Twitch accounts, so exposing am give receiving infrastructure account-level capabilities beyond video stream itself. One notable detail for implementation be say extension get separate workaround for 10 Russian channels wey no require forwarding user OAuth token. Available reporting no explain why that exception dey, so no attribute am to particular motive without supporting evidence.

Per The Hacker News, developer dispute claims say extension malicious. Developer note say after dem recognize security implications of forwarding users OAuth tokens, dem remove the feature for previous version. But tokens wey already transmit no dey automatically revoked just because extension update.

For anybody wey install Twitch Enhanced Viewer | JeetBot, immediate concern no be only whether extension still live, but whether e transmit OAuth token while e active. Valid token fit allow person make requests as account holder without knowing user Twitch password. So updating or removing extension addresses source of exposure but no by itself invalidate credentials wey may already leave device.

Twitch users suppose revoke or refresh active sessions and review recent account activity for unfamiliar messages, chat activity, setting changes, or other actions wey dem no perform. Users wey install Twitch Enhanced Viewer | JeetBot suppose remove or update extension, review accounts for unfamiliar activity, and invalidate any authorization credentials wey may don expose. Simply deleting extension or clearing browser data may not revoke OAuth token wey already transmit. Users suppose follow Twitch official account-security guidance for revoking connected applications or active authorizations and consider changing password if recommended.

But incident also expose less obvious problem with relying on developer-submitted disclosures. According to Socket, extension declared data practices no match what researchers observe, showing say privacy labels and data-collection declarations no suppose be trusted at face value. Users suppose still read those disclosures before installing extension. However, dem suppose also check permissions e request, what functionality actually require those permissions, who operate service behind am, and how often e dey updated.

Incident also underscore broader browser-extension security problem. Official store listings, long publishing histories, and developer-submitted privacy disclosures fit create appearance of trust without showing exactly what extension does once installed. Security teams suppose review permissions granted to browser extensions, external domains wey those extensions communicate with, and whether employees actually need access wey dem request. For tools wey fit interact with authenticated sessions, credential exposure suppose be treated as third-party access risk rather than simply browser issue.