A malicious Twitch browser extension leaked OAuth tokens from nearly 31,000 users to Russian proxy servers. Here's what happened and how to protect yourself.
So here's something that should make you pause before installing your next browser extension. A malicious Twitch extension quietly leaked OAuth tokens from nearly 31,000 users straight to proxy servers run by a Russian commercial bot service. Yeah. That's as bad as it sounds.
The extension went by the name "Twitch Enhanced Viewer | JeetBot," and it listed HISHIMIRO/jeetbot.cc as its developer. It was available on both the Google Chrome Web Store and the Mozilla Firefox Add-Ons store — which is exactly why this matters so much.
### What Actually Happened
OAuth tokens are the digital keys that let apps act on your behalf without needing your password. Think of them like a valet key for your car. Hand it over, and someone can drive your vehicle without ever touching your main keyring. That's the whole point — convenience.
But when those tokens get stolen, the thief doesn't need your password either. They just walk in like they own the place.
In this case, the stolen tokens gave whoever was behind the extension access to Twitch accounts, and possibly linked services too. The proxy servers tied to the bot service suggest the data wasn't just collected — it was likely packaged and resold.
### Why Cross-Store Extensions Are a Problem
Here's the part that bugs me. The same extension showed up on two major browser stores. That means it passed whatever review process both platforms have in place. Twice.
- Chrome Web Store listing under the same developer ID
- Firefox Add-Ons store listing with identical branding
- Both pointing back to the same suspicious domain
If you're wondering how something like this slips through, the answer is usually the same: automated review tools catch obvious malware, but quiet data siphoning is much harder to spot.
### The Bigger Lesson for Anyone Using Antidetect Browsers
If you work with antidetect browsers — whether for multi-accounting, affiliate marketing, or privacy research — this story should hit close to home. You're already trusting extensions, profiles, and tools to handle sensitive sessions. One bad add-on can undo a lot of careful setup.
A few things worth doing right now:
- Audit every extension you have installed and remove anything you don't actively use
- Check developer names and domains before clicking install
- Never grant OAuth permissions to tools you haven't vetted
- Rotate tokens and credentials regularly, especially on Twitch, Google, and Discord
> "The best antidetect browser setup in the world won't save you if you hand your tokens to the wrong extension."
That line isn't meant to scare you. It's just the truth. Security is layers, and the browser extension layer is one people forget about constantly.
### What to Do If You Think You're Affected
First, check whether "Twitch Enhanced Viewer | JeetBot" is installed on any browser profile you use. If it is, remove it immediately. Then head into your Twitch account settings and revoke any third-party app access you don't recognize.
Change your password too — even though the tokens bypass that step, it's still good hygiene after any breach. And if you reuse that password elsewhere, change it there as well.
### The Takeaway
Nearly 31,000 people trusted a browser extension to make Twitch a little nicer to use. Instead, their OAuth tokens ended up on servers tied to a bot operation. It's a reminder that convenience and security rarely ride in the same car — and when they do, one of them is usually driving blind.
If you're serious about privacy, treat every extension like a stranger asking for your keys. Because sometimes, that's exactly what it is.