Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Twitch Extension JeetBot Risks User Security

Twitch Extension JeetBot Risks User Security

Posted on September 14, 2026 By CWS

A browser extension claiming to enhance Twitch viewing has been found compromising user security. Known as “Twitch Enhanced Viewer | JeetBot,” this add-on was available for both Chrome and Firefox users and offered features like ad blocking, improved playback quality, and automatic channel-point collection.

Security Risks of JeetBot Extension

While the extension promised useful features, it posed significant security risks by rerouting Twitch playlist requests through third-party proxies. This process exposed users’ OAuth session tokens, transforming the extension into a potential account takeover tool. Socket.dev identified this vulnerability, noting the extension transmitted credentials for nearly every channel viewed by a user.

The extension had a significant user base, with approximately 30,000 installations on Chrome and 552 on Firefox, totaling around 31,000 users. The OAuth tokens were sent to infrastructure associated with a Russian commercial bot service, highlighting a disturbing trend of seemingly trustworthy add-ons misusing permissions.

Operational Mechanics and User Impact

The JeetBot extension did not need to deceive users into revealing passwords. Instead, it accessed the Authorization header from Twitch’s web client, forwarding this sensitive information to a proxy server. This token, more sensitive than those needed for video streaming, was used in proxy request logs and could enable unauthorized account access.

Despite different mechanisms employed by Firefox and Chrome, both browsers faced similar outcomes. The extension selectively excluded only a few Russian-language channels from this token forwarding, leaving most channels vulnerable. This behavior contradicted store disclosures claiming no user data collection or processing.

Recommendations and Precautions

Users who installed the JeetBot extension are advised to remove it immediately and disconnect all active sessions through Twitch account settings to invalidate compromised tokens. Reviewing recent account activity for unauthorized changes is also recommended.

Security teams should block the extension’s identified infrastructure at the network level and scrutinize browser extensions with access to authenticated services. Developers must avoid sending authentication tokens through third-party servers and ensure transparent communication about data handling practices.

As malicious extension activities continue to rise, maintaining vigilance over new permissions and updates becomes crucial for safeguarding online privacy and security.

Cyber Security News Tags:account takeover, authentication tokens, browser extension, Chrome, Cybersecurity, extension vulnerability, Firefox, JeetBot, malicious extensions, OAuth token, online privacy, proxy servers, Socket.dev, Twitch, user security

Post navigation

Previous Post: Critical Vulnerabilities in JFrog Artifactory Exploited
Next Post: New DDRop Attack Targets Intel and AMD Confidential Computing

Related Posts

20-Year-Old Vulnerability Allows Hackers to Control Train Brakes 20-Year-Old Vulnerability Allows Hackers to Control Train Brakes Cyber Security News
GentleKiller Exploits Drivers to Bypass 400+ Security Tools GentleKiller Exploits Drivers to Bypass 400+ Security Tools Cyber Security News
Cybersecurity: Key Exploits and Vulnerabilities of the Week Cybersecurity: Key Exploits and Vulnerabilities of the Week Cyber Security News
Starbucks Faces Cyber Breach: 10GB Data Allegedly Stolen Starbucks Faces Cyber Breach: 10GB Data Allegedly Stolen Cyber Security News
.NET 10.0.7 Update Fixes Critical Vulnerability .NET 10.0.7 Update Fixes Critical Vulnerability Cyber Security News
First Rowhammer Attack Targeting NVIDIA GPUs First Rowhammer Attack Targeting NVIDIA GPUs Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
  • New DDRop Attack Targets Intel and AMD Confidential Computing
  • Twitch Extension JeetBot Risks User Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
  • New DDRop Attack Targets Intel and AMD Confidential Computing
  • Twitch Extension JeetBot Risks User Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark