A browser extension claiming to enhance Twitch viewing has been found compromising user security. Known as “Twitch Enhanced Viewer | JeetBot,” this add-on was available for both Chrome and Firefox users and offered features like ad blocking, improved playback quality, and automatic channel-point collection.
Security Risks of JeetBot Extension
While the extension promised useful features, it posed significant security risks by rerouting Twitch playlist requests through third-party proxies. This process exposed users’ OAuth session tokens, transforming the extension into a potential account takeover tool. Socket.dev identified this vulnerability, noting the extension transmitted credentials for nearly every channel viewed by a user.
The extension had a significant user base, with approximately 30,000 installations on Chrome and 552 on Firefox, totaling around 31,000 users. The OAuth tokens were sent to infrastructure associated with a Russian commercial bot service, highlighting a disturbing trend of seemingly trustworthy add-ons misusing permissions.
Operational Mechanics and User Impact
The JeetBot extension did not need to deceive users into revealing passwords. Instead, it accessed the Authorization header from Twitch’s web client, forwarding this sensitive information to a proxy server. This token, more sensitive than those needed for video streaming, was used in proxy request logs and could enable unauthorized account access.
Despite different mechanisms employed by Firefox and Chrome, both browsers faced similar outcomes. The extension selectively excluded only a few Russian-language channels from this token forwarding, leaving most channels vulnerable. This behavior contradicted store disclosures claiming no user data collection or processing.
Recommendations and Precautions
Users who installed the JeetBot extension are advised to remove it immediately and disconnect all active sessions through Twitch account settings to invalidate compromised tokens. Reviewing recent account activity for unauthorized changes is also recommended.
Security teams should block the extension’s identified infrastructure at the network level and scrutinize browser extensions with access to authenticated services. Developers must avoid sending authentication tokens through third-party servers and ensure transparent communication about data handling practices.
As malicious extension activities continue to rise, maintaining vigilance over new permissions and updates becomes crucial for safeguarding online privacy and security.
