Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Twitch Extension Security Breach Exposes OAuth Tokens

Twitch Extension Security Breach Exposes OAuth Tokens

Posted on September 14, 2026 By CWS

A security flaw in a Twitch browser extension has compromised the OAuth tokens of nearly 31,000 users, sending them to proxy servers linked to a Russian bot service. The extension, ‘Twitch Enhanced Viewer | JeetBot,’ is available on both the Google Chrome Web Store and Mozilla Firefox Add-Ons store. It promises enhanced streaming capabilities, including 1080p quality for restricted regions.

Vulnerabilities in JeetBot Extension

The ‘Twitch Enhanced Viewer | JeetBot’ extension, developed by HISHIMIRO/jeetbot.cc, was found to forward OAuth tokens to the operator’s proxy servers. According to security researcher Kush Pandya from Socket, the extension uses a query parameter to transmit these tokens for every channel viewed, sparing only a select group of ten Russian channels. This information could enable unauthorized access to users’ private Twitch data, including chats and account settings.

The extension’s vulnerability stems from its method of routing Twitch’s video-playlist requests through these proxy servers, attaching the user’s token in the process. This effectively exposes sensitive user information, which is logged in cleartext on the proxy server. Despite the serious security implications, the extension remains available for download.

Details of the Token Exposure

The exposed OAuth tokens grant substantial access to user accounts, allowing actions such as reading and sending whispers, posting in chat, and spending channel points. This raises significant privacy concerns, given that the tokens are bearer credentials that do not require a password or second-factor authentication for access.

The extension’s earlier versions handled the tokens even less securely, posting them to a specific endpoint on the operator’s server. This was changed in the latest update, version 85.8.7 for Firefox, which now retrieves playlists without sending tokens to the proxy servers. However, users must update their extensions to benefit from these changes.

Steps Taken to Address the Issue

JeetBot’s developer, Aleksandr Popov, has acknowledged the security flaw and taken steps to mitigate the risk. The latest update for Firefox and an impending review for Chrome aim to resolve the issue by altering how playlists are accessed. Users are advised to update to version 85.8.7 or later to prevent further token transmission.

The developer also suggests temporarily disabling the extension to stop any ongoing token exposure. Nevertheless, previously transmitted tokens remain vulnerable. Until further notice, users are encouraged to stay vigilant and ensure their extensions are updated promptly.

The incident highlights the ongoing challenges in securing browser extensions and the potential risks they pose to user privacy. As the situation unfolds, The Hacker News is awaiting further comments from both Socket and the developer to provide additional insights into this security breach.

The Hacker News Tags:browser extension, Chrome, data breach, Firefox, JeetBot, Malware, OAuth tokens, Security, Streaming, Twitch

Post navigation

Previous Post: Hackers Use AutoIt to Conceal AsyncRAT in Windows
Next Post: Critical Patch Issued for ScreenConnect Vulnerability

Related Posts

[Webinar] Learn How Leading Security Teams Reduce Attack Surface Exposure with DASR [Webinar] Learn How Leading Security Teams Reduce Attack Surface Exposure with DASR The Hacker News
Cyber Espionage Targets Myanmar with QUICAgent Malware Cyber Espionage Targets Myanmar with QUICAgent Malware The Hacker News
North Korean Job Fraud Spreads to Healthcare and Sales North Korean Job Fraud Spreads to Healthcare and Sales The Hacker News
Critical Security Risks Skyrocket: OX Security’s 2026 Analysis Critical Security Risks Skyrocket: OX Security’s 2026 Analysis The Hacker News
The Evolution of UTA0388’s Espionage Malware The Evolution of UTA0388’s Espionage Malware The Hacker News
Validate Security Measures Against Real Threats Validate Security Measures Against Real Threats The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Patch Issued for ScreenConnect Vulnerability
  • Twitch Extension Security Breach Exposes OAuth Tokens
  • Hackers Use AutoIt to Conceal AsyncRAT in Windows
  • Urgent Alert on Check Point VPN Vulnerabilities
  • Critical Cybersecurity Updates: Microsoft, FortiOS, and More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Patch Issued for ScreenConnect Vulnerability
  • Twitch Extension Security Breach Exposes OAuth Tokens
  • Hackers Use AutoIt to Conceal AsyncRAT in Windows
  • Urgent Alert on Check Point VPN Vulnerabilities
  • Critical Cybersecurity Updates: Microsoft, FortiOS, and More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark