Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Twitch Extension Security Breach Exposes OAuth Tokens

Twitch Extension Security Breach Exposes OAuth Tokens

Posted on September 14, 2026 By CWS

A security flaw in a Twitch browser extension has compromised the OAuth tokens of nearly 31,000 users, sending them to proxy servers linked to a Russian bot service. The extension, ‘Twitch Enhanced Viewer | JeetBot,’ is available on both the Google Chrome Web Store and Mozilla Firefox Add-Ons store. It promises enhanced streaming capabilities, including 1080p quality for restricted regions.

Vulnerabilities in JeetBot Extension

The ‘Twitch Enhanced Viewer | JeetBot’ extension, developed by HISHIMIRO/jeetbot.cc, was found to forward OAuth tokens to the operator’s proxy servers. According to security researcher Kush Pandya from Socket, the extension uses a query parameter to transmit these tokens for every channel viewed, sparing only a select group of ten Russian channels. This information could enable unauthorized access to users’ private Twitch data, including chats and account settings.

The extension’s vulnerability stems from its method of routing Twitch’s video-playlist requests through these proxy servers, attaching the user’s token in the process. This effectively exposes sensitive user information, which is logged in cleartext on the proxy server. Despite the serious security implications, the extension remains available for download.

Details of the Token Exposure

The exposed OAuth tokens grant substantial access to user accounts, allowing actions such as reading and sending whispers, posting in chat, and spending channel points. This raises significant privacy concerns, given that the tokens are bearer credentials that do not require a password or second-factor authentication for access.

The extension’s earlier versions handled the tokens even less securely, posting them to a specific endpoint on the operator’s server. This was changed in the latest update, version 85.8.7 for Firefox, which now retrieves playlists without sending tokens to the proxy servers. However, users must update their extensions to benefit from these changes.

Steps Taken to Address the Issue

JeetBot’s developer, Aleksandr Popov, has acknowledged the security flaw and taken steps to mitigate the risk. The latest update for Firefox and an impending review for Chrome aim to resolve the issue by altering how playlists are accessed. Users are advised to update to version 85.8.7 or later to prevent further token transmission.

The developer also suggests temporarily disabling the extension to stop any ongoing token exposure. Nevertheless, previously transmitted tokens remain vulnerable. Until further notice, users are encouraged to stay vigilant and ensure their extensions are updated promptly.

The incident highlights the ongoing challenges in securing browser extensions and the potential risks they pose to user privacy. As the situation unfolds, The Hacker News is awaiting further comments from both Socket and the developer to provide additional insights into this security breach.

The Hacker News Tags:browser extension, Chrome, data breach, Firefox, JeetBot, Malware, OAuth tokens, Security, Streaming, Twitch

Post navigation

Previous Post: Hackers Use AutoIt to Conceal AsyncRAT in Windows
Next Post: Critical Patch Issued for ScreenConnect Vulnerability

Related Posts

Iranian Hackers Deploy Cavern C2 Framework on Israel Iranian Hackers Deploy Cavern C2 Framework on Israel The Hacker News
SEO-Poisoned Sites Exploit ScreenConnect for Malware SEO-Poisoned Sites Exploit ScreenConnect for Malware The Hacker News
New Win-DDoS Flaws Let Attackers Turn Public Domain Controllers into DDoS Botnet via RPC, LDAP New Win-DDoS Flaws Let Attackers Turn Public Domain Controllers into DDoS Botnet via RPC, LDAP The Hacker News
AI Automation Exploits, Telecom Espionage, Prompt Poaching & More AI Automation Exploits, Telecom Espionage, Prompt Poaching & More The Hacker News
North Korean Hackers Exploit Developer Tools for Cyber Attacks North Korean Hackers Exploit Developer Tools for Cyber Attacks The Hacker News
Prioritization, Validation, and Outcomes That Matter Prioritization, Validation, and Outcomes That Matter The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitHub Awards Record $100K for Major RCE Vulnerability
  • Telus Alerts Customers to Data Breach Incidents
  • Critical Patch Issued for ScreenConnect Vulnerability
  • Twitch Extension Security Breach Exposes OAuth Tokens
  • Hackers Use AutoIt to Conceal AsyncRAT in Windows

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitHub Awards Record $100K for Major RCE Vulnerability
  • Telus Alerts Customers to Data Breach Incidents
  • Critical Patch Issued for ScreenConnect Vulnerability
  • Twitch Extension Security Breach Exposes OAuth Tokens
  • Hackers Use AutoIt to Conceal AsyncRAT in Windows

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark