A recently identified malicious browser extension targeting Twitch users has resulted in the unauthorized exposure of OAuth tokens for approximately 31,000 accounts. The extension, named “Twitch Enhanced Viewer | JeetBot,” allegedly routes these tokens to proxy servers controlled by a Russian bot service. Researchers have raised concerns regarding the effective safeguarding of sensitive user credentials across the platforms involved.
The malicious extension, developed by HISHIMIRO/jeetbot.cc, has been available on both the Google Chrome Web Store and the Mozilla Firefox Add-Ons store. As of now, both versions remain downloadable, potentially putting thousands of users at risk. Users of the extension are drawn in by promises of enhanced viewing experience, claiming benefits such as ad-free streaming and access to 1080p content. However, a security analysis has revealed that the extension captures and transmits users’ OAuth tokens throughout their browsing sessions, except for a limited number of hardcoded exceptions.
According to Socket security researcher Kush Pandya, the mechanism by which the tokens are forwarded occurs through a network layer redirect that appends the token as an authentication query parameter. This process remains intact for most channels the users view, notably exempting a selected list of ten Russian-language Twitch channels. The extensive use of this token forwarding technique raises substantial concerns regarding user privacy and data security.
As this incident unfolds, it underscores the vulnerability of third-party extensions in handling sensitive authentication data. The fact that tokens are sent as query parameters, readable in clear text, means they could be easily logged and exploited by malicious actors. OAuth tokens serve as bearer credentials, allowing anyone in possession of them to perform actions on behalf of the user, including unauthorized messaging, chat interactions, and resource allocation.
In addressing the situation, the developer, Aleksandr Popov, indicated that the disclosure of token transmission was not adequately represented in the extension’s previous description or privacy policy. A new version of the extension has since been released, which is said to mitigate these vulnerabilities by changing how stream playlists are retrieved—specifically, eliminating the need to send OAuth tokens to proxy servers. However, users are cautioned that disabling or updating the extension does not retroactively revoke previously exposed tokens.
The incident predominantly targets Twitch users, and while the developers assist in resolving the issue, the broader implications about the reliance on unverified third-party extensions persist, emphasizing the need for users and developers alike to practice heightened vigilance. It appears that the compromised extension has exploited weaknesses primarily related to initial access and data exfiltration tactics within the MITRE ATT&CK framework.
As cybersecurity continues to be a pressing concern in an ever-evolving digital landscape, this incident serves as a reminder of the challenges posed by malicious software and the critical importance of safeguarding user credentials. Business owners are encouraged to engage in thorough assessments of third-party software and remain informed about the security measures necessary to protect sensitive data in their operations.