Twitch Extension Sent About 31,000 Users’ OAuth Tokens to JeetBot Proxies; Fixes Now Available

· Original article ↗

Summary

Socket found a Twitch extension forwarding OAuth session tokens for about 31,000 Chrome and Firefox users to JeetBot proxies. Fixed versions are now available; users should revoke existing Twitch sessions.

Key points

  • The Chrome and Firefox extension forwarded users’ Twitch OAuth session tokens to operator-controlled proxy servers while redirecting video playlist requests.
  • The exposed account-scoped tokens could enable actions such as reading or sending whispers, posting in chat, and spending channel points.
  • The extension omitted token forwarding for ten hardcoded channels; earlier v4.x builds also sent tokens to dedicated collection endpoints.
  • The extension had about 30,000 Chrome users and 552 Firefox users. The article reports no evidence that the tokens were misused.
  • Fixed versions are available: Firefox 85.8.7 and Chrome 85.8.9, according to the article’s updates.
  • Users should update the extension, disconnect Twitch sessions, and re-authenticate to invalidate tokens that may already have been forwarded.

Article Details

Attack Vectors
  • The extension captured the Authorization header used by Twitch’s web client and passed it from a content script to its background worker.
  • Before the fixes, the extension redirected video-playlist requests through operator proxies and appended the viewer’s account-scoped Twitch OAuth token as an &auth= query parameter. Ten hardcoded streamer channels were exempt from token forwarding.
  • Earlier v4.x builds POSTed captured tokens to set-token endpoints, with backup endpoints available.
Defensive Notes
  • Update the extension to version 85.8.7 or later. The source confirms the token-forwarding fix in Firefox 85.8.7 and Chrome 85.8.9.
  • Affected users should disconnect all Twitch sessions and re-authenticate to invalidate previously forwarded tokens.
  • Security teams should inventory both extension IDs, flag versions before 85.8.7, and have affected users revoke their Twitch sessions.
  • Developers should strip authentication credentials before proxying requests through third-party servers and prominently disclose proxying.

Indicators of compromise

TypeIndicatorContext
DOMAINjeetbot[.]ccOperator control endpoint identified alongside the token-receiving proxy.
HOSTNAMEapi[.]jeetbot[.]ccOperator control endpoint identified alongside the token-receiving proxy.
HOSTNAMEenhanced-1[.]jeetbot[.]ccAlternate extension proxy listed in the revised IOC section.
HOSTNAMEenhanced[.]jeetbot[.]ccDefault operator proxy that received forwarded Twitch OAuth tokens in affected versions.
HOSTNAMEext-03[.]jeetbot[.]ccAlternate extension proxy.
HOSTNAMEext-styles[.]jeetbot[.]ccOperator configuration API host used to supply the extension’s proxy catalog.
HOSTNAMEimg[.]drisnya[.]onlineScreenshot host listed among the extension infrastructure indicators.
HOSTNAMEproxy[.]morphilina[.]meOperator token-strip proxy; the source states it did not receive the token.
IPV4132[.]243[.]113[.]25IP address hosting the extension’s configuration API, token-strip proxy, and screenshot hosts.
IPV4152[.]53[.]177[.]186IP address hosting the default proxy that received forwarded tokens and JeetBot control endpoints.
IPV480[.]74[.]26[.]162IP address hosting an alternate extension proxy.
SHA256141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fcSHA-256 listed for the Firefox extension.
SHA256e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8SHA-256 listed for the Chrome extension.
URLhxxps[:]//ext-styles[.]jeetbot[.]cc/api/v1/proxiesOperator proxy-catalog API URL defined in the extension code.

MITRE ATT&CK

People

Vendors

Products

Countries

Industries

Related Articles