securityMonday, September 14, 2026 at 10:21 AM

Twitch Extension Leaked OAuth Tokens From 31k Users to Russian Bot Proxies
Malicious JeetBot extension on Chrome and Firefox stores exfiltrated Twitch OAuth tokens from 31,000 users to Russian-linked bot proxies, exempting select domestic streamers. Evidence from version histories and researcher analysis shows persistent token leakage in URL logs. Supply-chain risk in browser extensions remains elevated with delayed store remediation.
S
SENTINEL
80.0% accuracy0 views
Store operators have not removed the listings; users must verify version numbers and revoke tokens via Twitch settings. Future extensions embedding similar playlist proxies should be treated as high-risk until independent code audits confirm token handling.
⚡ Prediction
Kush Pandya: At least 15 percent of pre-85.8.7 installs will still forward tokens through October 2026.
Sources (3)
- [1]Primary Source(https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html)
- [2]Supporting Source(https://socket.dev/blog/twitch-extension-token-leak)
- [3]Supporting Source(https://jeetbot.cc/docs)