Twitch Extension Exposed OAuth Tokens to Developer

eSecurity Planet · Medium sophistication
Last updated September 15, 2026

Researchers reported that a popular Twitch browser extension sent users’ Twitch OAuth login tokens to proxy servers controlled by the extension’s developer. If a token was exposed, someone receiving it could potentially act as the account holder without needing the user’s password. The key user risk is that uninstalling or updating the extension may not automatically revoke tokens that were already transmitted.

Key findings

  • A Twitch browser extension with ~30,000 Chrome users allegedly transmitted Twitch OAuth tokens to infrastructure controlled by its developer.
  • The extension advertised viewer features (higher-quality playback, ad blocking, channel-point collection) but could also extract tokens from authenticated Twitch sessions and attach them to requests sent through developer-controlled proxies.
  • Socket warned that the transmitted token could provide account-level capabilities (read/write actions) beyond what’s required for video playback.
  • The extension appeared established (published June/July 2025) and remained live in the official Chrome/Firefox stores at the time of reporting.
  • Updating/removing the extension may stop further exposure but does not automatically revoke tokens that may already have been transmitted.

Who’s being targeted

  • Commonly targeted roles: All employees (browser users), IT / Endpoint Management, Security Awareness, Security Operations, Marketing/Social Media teams.
  • Affected industries: Media and streaming platforms, Consumer internet services, Any organization allowing browser extensions on corporate endpoints.
  • Attack channels: website.
  • Impersonated: A legitimate Twitch utility extension in the official Chrome/Firefox stores (Twitch Enhanced Viewer | JeetBot), Twitch playback/proxy helper operated by the extension developer (JeetBot-controlled proxy servers).

Awareness takeaways

  • Treat browser extensions as third-party access risk, especially if they can interact with logged-in sessions.
  • Uninstalling or updating a risky extension may not be enough, revoke sessions/authorizations and review account activity.
  • Don’t rely solely on ‘official store’ trust signals (age, popularity, privacy labels); validate permissions and network behavior.
  • Implement enterprise controls: review/limit extension permissions and monitor the external domains extensions communicate with.

Red flags to watch for

  • Extension requests/uses access that isn’t necessary for the advertised features
  • Traffic is routed through “developer-controlled proxy servers”
  • Sensitive credentials (tokens) are transmitted off-device
  • A video/quality feature unexpectedly requires routing traffic through third-party proxies
  • A feature set that does not justify transmitting authentication tokens
  • Mismatch between store ‘data practices’ labels and observed behavior
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You install a Twitch helper called “Twitch Enhanced Viewer | JeetBot” from the official Chrome store… and it quietly gets the power to be you. Researchers found this JeetBot extension was grabbing your Twitch OAuth token from your logged-in session and sending it through JeetBot-controlled proxy servers, letting someone act as your account without your password. Here’s the trap: the extension says it routes playlists through its proxy to unlock 1080p in restricted regions, but that video feature does not need full read/write account access. And even if you uninstall it, any token it already sent can still work. If you’ve ever used a Twitch enhancement extension like this, don’t just delete it, log into Twitch, kill old sessions and connected apps, and scan your account activity for anything you don’t recognize.

MITRE ATT&CK techniques

Similar attacks

npm Mirrors Used for Fake Cloudflare CAPTCHA Phish

npm Mirrors Used for Fake Cloudflare CAPTCHA Phish

Researchers found a real phishing campaign abusing npm packages and unpkg mirrors to host a convincing fake Cloudflare CAPTCHA page on a trusted domain. Victims who click the mirrored link are redirected to attacker-controlled infrastructure that could deliver ClickFix-style prompts or credential…

August 25, 2026
Greatness PhaaS Adds Device-Code MFA Bypass

Greatness PhaaS Adds Device-Code MFA Bypass

Criminals using the “Greatness” phishing-as-a-service kit are running real-world phishing campaigns that trick employees into approving a Microsoft device-code login flow, allowing attackers to bypass MFA and steal access tokens. Recent activity includes RingCentral “voicemail” lures and multi-step…

August 4, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Passkey-Themed Phishing Hits Microsoft 365

Passkey-Themed Phishing Hits Microsoft 365

Microsoft warns of an active social engineering campaign where attackers pose as an IT help desk and pressure employees to “update” passkeys/MFA/SSO. Victims are sent to fake Microsoft sign-in pages or tricked into approving access via device-code login, enabling attackers to add their own MFA…

September 14, 2026
ClickFix Sites Trick Macs Into Running Malware Commands

ClickFix Sites Trick Macs Into Running Malware Commands

A real ClickFix campaign used 250+ lookalike domains and browser fingerprinting to show malware lures mainly to real macOS visitors while showing harmless decoys to scanners and researchers. Victims were pushed to copy and run an obfuscated command in macOS Terminal, which then downloaded and…

August 6, 2026
Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access without stealing passwords. It highlights rapid criminal adoption via phishing-as-a-service kits and notes heavy targeting of Microsoft…

July 31, 2026