Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Twitch extension exposed OAuth tokens for 31,000 users via Russian proxy network

A browser extension for Twitch exposed users’ OAuth tokens by sending them to a Russian-owned proxy server, according to security researchers at Socket.

Called “Twitch Enhanced Viewer | JeeBot”, the extension had roughly 30,000 users on Chrome and about 600 on Firefox. It advertised tools for clearer streaming and viewing, 2K playback, banner-ad removal and an AI bot for interacting with streams.

Socket said the extension retrieved Twitch video-stream playlists through its own proxy servers. Instead of forwarding only the requests, it attached users’ OAuth tokens to the URLs. Those tokens could then appear in the proxy server’s request logs.

The developer, HISHIMIRO/jeetbot.cc, released version 85.8.7 for Firefox after the issue was reported. The Chrome version was still under review. The update apparently stops the extension from sending OAuth tokens to the proxies when retrieving playlists.

Socket said current v85.x builds forwarded the token through an &auth= query parameter for every channel watched, except for a hardcoded allowlist of ten Russian streamer channels. The exception raised questions about whether the token-handling behavior was deliberate.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.