Twitch Extension Sent About 31,000 Users’ OAuth Tokens to JeetBot Proxies; Fixes Now Available

Summary
Socket found a Twitch extension forwarding OAuth session tokens for about 31,000 Chrome and Firefox users to JeetBot proxies. Fixed versions are now available; users should revoke existing Twitch sessions.
Key points
- The Chrome and Firefox extension forwarded users’ Twitch OAuth session tokens to operator-controlled proxy servers while redirecting video playlist requests.
- The exposed account-scoped tokens could enable actions such as reading or sending whispers, posting in chat, and spending channel points.
- The extension omitted token forwarding for ten hardcoded channels; earlier v4.x builds also sent tokens to dedicated collection endpoints.
- The extension had about 30,000 Chrome users and 552 Firefox users. The article reports no evidence that the tokens were misused.
- Fixed versions are available: Firefox 85.8.7 and Chrome 85.8.9, according to the article’s updates.
- Users should update the extension, disconnect Twitch sessions, and re-authenticate to invalidate tokens that may already have been forwarded.
Article Details
- Attack Vectors
- The extension captured the Authorization header used by Twitch’s web client and passed it from a content script to its background worker.
- Before the fixes, the extension redirected video-playlist requests through operator proxies and appended the viewer’s account-scoped Twitch OAuth token as an &auth= query parameter. Ten hardcoded streamer channels were exempt from token forwarding.
- Earlier v4.x builds POSTed captured tokens to set-token endpoints, with backup endpoints available.
- Defensive Notes
- Update the extension to version 85.8.7 or later. The source confirms the token-forwarding fix in Firefox 85.8.7 and Chrome 85.8.9.
- Affected users should disconnect all Twitch sessions and re-authenticate to invalidate previously forwarded tokens.
- Security teams should inventory both extension IDs, flag versions before 85.8.7, and have affected users revoke their Twitch sessions.
- Developers should strip authentication credentials before proxying requests through third-party servers and prominently disclose proxying.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | jeetbot[.]cc | Operator control endpoint identified alongside the token-receiving proxy. |
| HOSTNAME | api[.]jeetbot[.]cc | Operator control endpoint identified alongside the token-receiving proxy. |
| HOSTNAME | enhanced-1[.]jeetbot[.]cc | Alternate extension proxy listed in the revised IOC section. |
| HOSTNAME | enhanced[.]jeetbot[.]cc | Default operator proxy that received forwarded Twitch OAuth tokens in affected versions. |
| HOSTNAME | ext-03[.]jeetbot[.]cc | Alternate extension proxy. |
| HOSTNAME | ext-styles[.]jeetbot[.]cc | Operator configuration API host used to supply the extension’s proxy catalog. |
| HOSTNAME | img[.]drisnya[.]online | Screenshot host listed among the extension infrastructure indicators. |
| HOSTNAME | proxy[.]morphilina[.]me | Operator token-strip proxy; the source states it did not receive the token. |
| IPV4 | 132[.]243[.]113[.]25 | IP address hosting the extension’s configuration API, token-strip proxy, and screenshot hosts. |
| IPV4 | 152[.]53[.]177[.]186 | IP address hosting the default proxy that received forwarded tokens and JeetBot control endpoints. |
| IPV4 | 80[.]74[.]26[.]162 | IP address hosting an alternate extension proxy. |
| SHA256 | 141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc | SHA-256 listed for the Firefox extension. |
| SHA256 | e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8 | SHA-256 listed for the Chrome extension. |
| URL | hxxps[:]//ext-styles[.]jeetbot[.]cc/api/v1/proxies | Operator proxy-catalog API URL defined in the extension code. |
MITRE ATT&CK
T1071.001 · Web ProtocolsAffected builds forwarded tokens in HTTPS proxy-request URLs; earlier builds POSTed tokens to set-token endpoints.T1176 · Software ExtensionsThe browser extension used its access to Twitch pages and requests to capture and forward account-scoped OAuth tokens.T1557 · Adversary-in-the-MiddleThe extension redirected authenticated video-playlist requests through operator proxies, forwarding the viewer’s OAuth token with the request.
People
Vendors
JeetBotUpdate, September 16, 2026: After publication, the JeetBot team reached out to us. They acknowledged the security risk of the token handling and that the extension's store description and privacy policy did notTwitchthat Chrome Web Store version 85.8.9 (the current version at this time) no longer forwards the viewer's Twitch OAuth token to the proxy. We've also revised the IOC section and removed the recommendation to block all
Products
Chrome Web StoreUpdate, September 25, 2026: The fix is live on the Chrome Web Store. We confirmed that Chrome Web Store version 85.8.9 (the current version at this time) no longer forwards the viewer's Twitch OAuth token to the proxy.Firefox Add-onsships on both the Chrome Web Store (extension ID pnhhdhhcadcjfckjhpmjneldiegbojfb, 30,000 users) and Firefox Add-ons (twitchenhancedviewer@example.com, 552 users). Both listings are live at time of writing.Google ChromeUpdate, September 25, 2026: The fix is live on the Chrome Web Store. We confirmed that Chrome Web Store version 85.8.9 (the current version at this time) no longer forwards the viewer's Twitch OAuth token to the proxy.Mozilla Firefoxdid not adequately disclose it, and they released a fix. We confirmed the remediation in the code: Firefox version 85.8.7 no longer forwards the viewer's Twitch OAuth token to the proxy (the auth parameter is nowTwitchthat Chrome Web Store version 85.8.9 (the current version at this time) no longer forwards the viewer's Twitch OAuth token to the proxy. We've also revised the IOC section and removed the recommendation to block allTwitch Enhanced Viewer | JeetBotSocket’s Threat Research Team identified a cross-store browser extension, “Twitch Enhanced Viewer | JeetBot,” that forwards each user's live Twitch OAuth session token to third-party proxy servers operated by the