Twitch Extension Leaks OAuth Tokens of Thousands of Users, Security Alert Issued
A security investigation has revealed that a popular browser add‑on, marketed as Twitch Enhanced Viewer | JeetBot, is transmitting Twitch OAuth session tokens from its users to an external commercial bot service, potentially exposing accounts to unauthorized access.
The extension, which is listed in both the Chrome Web Store and Mozilla Firefox Add‑ons site, has amassed roughly 30,000 installations since its release. It is promoted as a tool to enhance the viewing experience on Twitch, but the hidden data‑exfiltration behavior was uncovered by independent researchers and first reported by BleepingComputer.
OAuth tokens are cryptographic strings that grant the holder the same privileges as the user who generated them, allowing actions such as chat participation, channel subscriptions, and even broadcasting. By siphoning these tokens, the extension effectively hands over full account control to the third‑party service without the user’s knowledge.
Analysis of the extension’s code showed that, after a user logs into Twitch through the add‑on, the token is captured and sent via an HTTP request to a remote server operated by the bot service. The traffic was observable in network logs and could be reproduced on multiple test accounts, confirming that the behavior is systematic rather than an isolated glitch.
Security experts warn that malicious actors could use the harvested tokens to impersonate users, post spam, or manipulate streams, potentially compromising both personal accounts and the broader Twitch community. Since the tokens remain valid until the user revokes them or changes their password, the window of exposure could be significant.
Twitch has not yet issued an official statement regarding the specific extension, but the platform’s developer policies prohibit extensions from collecting authentication credentials. In similar past incidents, Twitch has acted swiftly to remove offending add‑ons and advise users to revoke compromised tokens.
Users who have installed Twitch Enhanced Viewer | JeetBot are urged to uninstall the extension immediately, revoke any active OAuth authorizations from their Twitch security settings, and consider enabling two‑factor authentication for added protection. Monitoring account activity for unfamiliar actions is also recommended.
The incident underscores a broader challenge in the browser‑extension ecosystem, where thousands of add‑ons undergo limited scrutiny before reaching public stores. Security researchers have repeatedly highlighted the need for more rigorous vetting and transparent permission disclosures to prevent similar exploits.
As the investigation continues, both Twitch and the browser‑store operators are expected to review their extension approval processes. Meanwhile, users are reminded to exercise caution when granting third‑party tools access to their accounts, ensuring that only trusted software with clear privacy practices is installed.
Comments (0)
Be the first to comment.
Join the discussion