A popular Twitch extension with over 30,000 installs was secretly sending users' OAuth session tokens to a commercial bot service. Here's what happened and how to protect yourself.
You know that little extension sitting in your browser right now? The one you installed months ago and forgot about? Yeah, that one. It turns out one popular Twitch add-on was doing something far sketchier than adding chat features. It was quietly passing your login credentials to a commercial bot service. And it had over 30,000 installs.
Let's talk about what actually happened, why it matters, and what you should do about it.
### What Is the Twitch Enhanced Viewer Extension?
A browser extension called **Twitch Enhanced Viewer | JeetBot** was available in both the official Chrome and Firefox stores. On the surface, it looked like a handy tool for improving your Twitch viewing experience. Nothing flashy. Nothing suspicious. Just another free add-on.
But underneath, it was sending users' Twitch OAuth session tokens to a commercial bot service. If you're not familiar with OAuth tokens, think of them like a temporary key to your account. You don't hand over your password, but you do hand over something almost as powerful.
Once someone has that token, they can act as you. Follow channels. Send messages. Access account data. All without ever knowing your password.
> "A session token is basically a signed permission slip. If it lands in the wrong hands, the damage is done before you even notice."
### Why This Should Get Your Attention
Here's the thing. This isn't some obscure piece of malware you'd have to download from a shady forum. This extension lived in the same stores you trust for your everyday browsing.
- It was available on Chrome and Firefox, two of the most widely used browsers in the U.S.
- It had over 30,000 installs, meaning tens of thousands of people were potentially affected.
- It sent OAuth tokens to a third-party bot service, which could use them for automation, spam, or worse.
- There was no obvious warning sign for the average user.
That last point is what stings. Most people install extensions the same way they click "I agree" on terms of service. Quickly. Without reading. Without thinking twice.
### The Bigger Problem With Browser Extensions
Browser extensions are one of the most overlooked security risks in everyday browsing. We treat them like apps on our phone. Install, forget, move on.
But extensions can read page content, access cookies, intercept network requests, and in some cases, grab authentication tokens. That's a lot of power for something you installed to make chat look nicer.
And once a token is stolen, it doesn't expire immediately. Attackers can keep using it until the session is revoked or times out. In some cases, that window is hours. In others, it's much longer.
### What You Can Do Right Now
If you've ever installed a Twitch-related extension, it's worth a quick audit. Here's a simple checklist:
- Open your browser's extension manager and review everything you've installed.
- Remove anything you don't actively use or recognize.
- Check your Twitch account's connected apps and revoke access for anything unfamiliar.
- Change your Twitch password if you suspect a token was compromised.
- Enable two-factor authentication if you haven't already.
It takes five minutes. Maybe less. And it could save you a headache that lasts way longer.
### The Takeaway
Free tools aren't always free. Sometimes the cost is your data, your account, or your privacy. This Twitch extension is just one example of how a harmless-looking add-on can turn into a real problem.
So next time you hit that "Add to Chrome" button, pause for a second. Ask yourself who's really behind it, and what they might want in return. Your login credentials are worth more than a smoother chat experience.