Skip to main content

Malicious Twitch Browser Extension Exposes 30,000 Users' OAuth Tokens to Russian Bot Service

0
Medium
Published: 09/11/2026 (09/11/2026, 18:06:36 UTC)
Source: AlienVault OTX General

Description

A malicious browser extension called 'Twitch Enhanced Viewer | JeetBot' distributed on Chrome Web Store and Firefox Add-ons captures and forwards users' live Twitch OAuth session tokens to Russian-controlled proxy servers. The extension, with approximately 30,000 Chrome users and 552 Firefox users, markets itself as a quality-of-life tool for blocking ads and unlocking streams. While delivering these features, it secretly extracts users' account-scoped OAuth tokens and forwards them as query parameters to operator-controlled infrastructure. Current versions append tokens inline during video playlist redirects, while earlier builds explicitly POSTed tokens to dedicated collection endpoints. The operator is identified as a commercial Russian bot service called JeetBot, with infrastructure hosted across German and cloud providers.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/14/2026, 10:20:52 UTC

Technical Analysis

The threat involves a malicious browser extension targeting Twitch users by capturing their OAuth session tokens. These tokens, which grant account-scoped access, are exfiltrated to infrastructure controlled by a Russian bot service named JeetBot. The extension is distributed through official browser extension stores and masquerades as a tool to improve Twitch viewing experience. Token exfiltration methods include appending tokens as query parameters during video playlist redirects in current versions and explicit POST requests in earlier versions. The infrastructure used for this operation is hosted across German and cloud providers, indicating a commercial bot service operation.

Potential Impact

Users of the malicious extension have their Twitch OAuth tokens stolen, potentially allowing unauthorized access to their Twitch accounts within the scope of those tokens. This compromises user privacy and security, enabling the attacker to impersonate users or perform actions on their behalf. The scale affects approximately 30,000 Chrome users and 552 Firefox users. There is no indication of active exploitation beyond token theft, and no known exploits in the wild have been reported.

Defensive Guidance

No official patch or fix is available since this is a malicious third-party browser extension rather than a software vulnerability. Users should immediately uninstall the 'Twitch Enhanced Viewer | JeetBot' extension from their browsers. Twitch users should consider revoking OAuth tokens associated with the extension via their Twitch account settings to invalidate stolen tokens. Caution is advised when installing browser extensions, especially those that request extensive permissions or come from untrusted sources.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://socket.dev/blog/malicious-twitch-browser-extension"]
Adversary
JeetBot
Pulse Id
6aa4432cfc2e960cdf6ac1e0

Indicators of Compromise

Hash

ValueDescriptionCopy
hash141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc
hashe17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8

Ip

ValueDescriptionCopy
ip132.243.113.25
ip80.74.26.162

Url

ValueDescriptionCopy
urlhttp://api.jeetbot.cc/api/v2/public/extension_helper/
urlhttp://enhanced.jeetbot.cc/set-token
urlhttp://ext-styles.jeetbot.cc/api/v1/forced-proxy
urlhttp://ext-styles.jeetbot.cc/api/v1/proxies
urlhttp://proxy.thebeholder.deno.net/set-token
urlhttp://thebeholder-proxy.deno.dev/set-token
urlhttps://enhanced.jeetbot.cc/
urlhttps://ext-styles.jeetbot.cc/api/v1/proxies
urlhttps://proxy.morphilina.me/
urlhttps://proxy.thebeholder.deno.net/
urlhttps://thebeholder-proxy.deno.dev/

Domain

ValueDescriptionCopy
domainalexue4.dev
domainmorphilina.me
domainjeetbot.cc
domainapi.jeetbot.cc
domainenhanced-1.jeetbot.cc
domainenhanced.jeetbot.cc
domainext-03.jeetbot.cc
domainext-styles.jeetbot.cc
domainimg.drisnya.online
domainproxy.morphilina.me
domainproxy.thebeholder.deno.net
domainthebeholder-proxy.deno.dev

Threat ID: 6aa7c61b55bf5e2cf5e00f65

Added to database: 09/14/2026, 10:02:03 UTC

Last enriched: 09/14/2026, 10:20:52 UTC

Last updated: 09/15/2026, 03:10:00 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses