Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Twitch Extension JeetBot Risks User Security

Twitch Extension JeetBot Risks User Security

Posted on September 14, 2026 By CWS

A browser extension claiming to enhance Twitch viewing has been found compromising user security. Known as “Twitch Enhanced Viewer | JeetBot,” this add-on was available for both Chrome and Firefox users and offered features like ad blocking, improved playback quality, and automatic channel-point collection.

Security Risks of JeetBot Extension

While the extension promised useful features, it posed significant security risks by rerouting Twitch playlist requests through third-party proxies. This process exposed users’ OAuth session tokens, transforming the extension into a potential account takeover tool. Socket.dev identified this vulnerability, noting the extension transmitted credentials for nearly every channel viewed by a user.

The extension had a significant user base, with approximately 30,000 installations on Chrome and 552 on Firefox, totaling around 31,000 users. The OAuth tokens were sent to infrastructure associated with a Russian commercial bot service, highlighting a disturbing trend of seemingly trustworthy add-ons misusing permissions.

Operational Mechanics and User Impact

The JeetBot extension did not need to deceive users into revealing passwords. Instead, it accessed the Authorization header from Twitch’s web client, forwarding this sensitive information to a proxy server. This token, more sensitive than those needed for video streaming, was used in proxy request logs and could enable unauthorized account access.

Despite different mechanisms employed by Firefox and Chrome, both browsers faced similar outcomes. The extension selectively excluded only a few Russian-language channels from this token forwarding, leaving most channels vulnerable. This behavior contradicted store disclosures claiming no user data collection or processing.

Recommendations and Precautions

Users who installed the JeetBot extension are advised to remove it immediately and disconnect all active sessions through Twitch account settings to invalidate compromised tokens. Reviewing recent account activity for unauthorized changes is also recommended.

Security teams should block the extension’s identified infrastructure at the network level and scrutinize browser extensions with access to authenticated services. Developers must avoid sending authentication tokens through third-party servers and ensure transparent communication about data handling practices.

As malicious extension activities continue to rise, maintaining vigilance over new permissions and updates becomes crucial for safeguarding online privacy and security.

Cyber Security News Tags:account takeover, authentication tokens, browser extension, Chrome, Cybersecurity, extension vulnerability, Firefox, JeetBot, malicious extensions, OAuth token, online privacy, proxy servers, Socket.dev, Twitch, user security

Post navigation

Previous Post: Critical Vulnerabilities in JFrog Artifactory Exploited
Next Post: New DDRop Attack Targets Intel and AMD Confidential Computing

Related Posts

LokiBot Campaign Revives with Advanced Evasion Techniques LokiBot Campaign Revives with Advanced Evasion Techniques Cyber Security News
Windows 11 App Promotes Bing in Major Browsers Windows 11 App Promotes Bing in Major Browsers Cyber Security News
Threat Actors Embed Malicious RMM Tools to Gain Silent Initial Access to Organizations Threat Actors Embed Malicious RMM Tools to Gain Silent Initial Access to Organizations Cyber Security News
Claude’s New Feature Simplifies AI Memory Transfer Claude’s New Feature Simplifies AI Memory Transfer Cyber Security News
New Maranhão Stealer Via Pirated Software Leveraging Cloud-Hosted Platforms to Steal Login Credentials New Maranhão Stealer Via Pirated Software Leveraging Cloud-Hosted Platforms to Steal Login Credentials Cyber Security News
BTMOB Malware Enables Remote Android Control BTMOB Malware Enables Remote Android Control Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
  • New DDRop Attack Targets Intel and AMD Confidential Computing
  • Twitch Extension JeetBot Risks User Security
  • Critical Vulnerabilities in JFrog Artifactory Exploited
  • WordPress Automates Plugin Security Reviews to Prevent Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack
  • New DDRop Attack Targets Intel and AMD Confidential Computing
  • Twitch Extension JeetBot Risks User Security
  • Critical Vulnerabilities in JFrog Artifactory Exploited
  • WordPress Automates Plugin Security Reviews to Prevent Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark