Malicious Twitch Browser Extension Exposes 30,000 Users' OAuth Tokens to Russian Bot Service
A malicious browser extension called 'Twitch Enhanced Viewer | JeetBot' distributed on Chrome Web Store and Firefox Add-ons captures and forwards users' live Twitch OAuth session tokens to Russian-controlled proxy servers. The extension, with approximately 30,000 Chrome users and 552 Firefox users, markets itself as a quality-of-life tool for blocking ads and unlocking streams. While delivering these features, it secretly extracts users' account-scoped OAuth tokens and forwards them as query parameters to operator-controlled infrastructure. Current versions append tokens inline during video playlist redirects, while earlier builds explicitly POSTed tokens to dedicated collection endpoints. The operator is identified as a commercial Russian bot service called JeetBot, with infrastructure hosted across German and cloud providers.
AI Analysis
Technical Summary
The threat involves a malicious browser extension targeting Twitch users by capturing their OAuth session tokens. These tokens, which grant account-scoped access, are exfiltrated to infrastructure controlled by a Russian bot service named JeetBot. The extension is distributed through official browser extension stores and masquerades as a tool to improve Twitch viewing experience. Token exfiltration methods include appending tokens as query parameters during video playlist redirects in current versions and explicit POST requests in earlier versions. The infrastructure used for this operation is hosted across German and cloud providers, indicating a commercial bot service operation.
Potential Impact
Users of the malicious extension have their Twitch OAuth tokens stolen, potentially allowing unauthorized access to their Twitch accounts within the scope of those tokens. This compromises user privacy and security, enabling the attacker to impersonate users or perform actions on their behalf. The scale affects approximately 30,000 Chrome users and 552 Firefox users. There is no indication of active exploitation beyond token theft, and no known exploits in the wild have been reported.
Mitigation Recommendations
No official patch or fix is available since this is a malicious third-party browser extension rather than a software vulnerability. Users should immediately uninstall the 'Twitch Enhanced Viewer | JeetBot' extension from their browsers. Twitch users should consider revoking OAuth tokens associated with the extension via their Twitch account settings to invalidate stolen tokens. Caution is advised when installing browser extensions, especially those that request extensive permissions or come from untrusted sources.
Indicators of Compromise
- hash: 141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc
- hash: e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8
- ip: 132.243.113.25
- ip: 80.74.26.162
- url: http://api.jeetbot.cc/api/v2/public/extension_helper/
- url: http://enhanced.jeetbot.cc/set-token
- url: http://ext-styles.jeetbot.cc/api/v1/forced-proxy
- url: http://ext-styles.jeetbot.cc/api/v1/proxies
- url: http://proxy.thebeholder.deno.net/set-token
- url: http://thebeholder-proxy.deno.dev/set-token
- url: https://enhanced.jeetbot.cc/
- url: https://ext-styles.jeetbot.cc/api/v1/proxies
- url: https://proxy.morphilina.me/
- url: https://proxy.thebeholder.deno.net/
- url: https://thebeholder-proxy.deno.dev/
- domain: alexue4.dev
- domain: morphilina.me
- domain: jeetbot.cc
- domain: api.jeetbot.cc
- domain: enhanced-1.jeetbot.cc
- domain: enhanced.jeetbot.cc
- domain: ext-03.jeetbot.cc
- domain: ext-styles.jeetbot.cc
- domain: img.drisnya.online
- domain: proxy.morphilina.me
- domain: proxy.thebeholder.deno.net
- domain: thebeholder-proxy.deno.dev
Malicious Twitch Browser Extension Exposes 30,000 Users' OAuth Tokens to Russian Bot Service
Description
A malicious browser extension called 'Twitch Enhanced Viewer | JeetBot' distributed on Chrome Web Store and Firefox Add-ons captures and forwards users' live Twitch OAuth session tokens to Russian-controlled proxy servers. The extension, with approximately 30,000 Chrome users and 552 Firefox users, markets itself as a quality-of-life tool for blocking ads and unlocking streams. While delivering these features, it secretly extracts users' account-scoped OAuth tokens and forwards them as query parameters to operator-controlled infrastructure. Current versions append tokens inline during video playlist redirects, while earlier builds explicitly POSTed tokens to dedicated collection endpoints. The operator is identified as a commercial Russian bot service called JeetBot, with infrastructure hosted across German and cloud providers.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat involves a malicious browser extension targeting Twitch users by capturing their OAuth session tokens. These tokens, which grant account-scoped access, are exfiltrated to infrastructure controlled by a Russian bot service named JeetBot. The extension is distributed through official browser extension stores and masquerades as a tool to improve Twitch viewing experience. Token exfiltration methods include appending tokens as query parameters during video playlist redirects in current versions and explicit POST requests in earlier versions. The infrastructure used for this operation is hosted across German and cloud providers, indicating a commercial bot service operation.
Potential Impact
Users of the malicious extension have their Twitch OAuth tokens stolen, potentially allowing unauthorized access to their Twitch accounts within the scope of those tokens. This compromises user privacy and security, enabling the attacker to impersonate users or perform actions on their behalf. The scale affects approximately 30,000 Chrome users and 552 Firefox users. There is no indication of active exploitation beyond token theft, and no known exploits in the wild have been reported.
Defensive Guidance
No official patch or fix is available since this is a malicious third-party browser extension rather than a software vulnerability. Users should immediately uninstall the 'Twitch Enhanced Viewer | JeetBot' extension from their browsers. Twitch users should consider revoking OAuth tokens associated with the extension via their Twitch account settings to invalidate stolen tokens. Caution is advised when installing browser extensions, especially those that request extensive permissions or come from untrusted sources.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://socket.dev/blog/malicious-twitch-browser-extension"]
- Adversary
- JeetBot
- Pulse Id
- 6aa4432cfc2e960cdf6ac1e0
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc | — | |
hashe17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8 | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip132.243.113.25 | — | |
ip80.74.26.162 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://api.jeetbot.cc/api/v2/public/extension_helper/ | — | |
urlhttp://enhanced.jeetbot.cc/set-token | — | |
urlhttp://ext-styles.jeetbot.cc/api/v1/forced-proxy | — | |
urlhttp://ext-styles.jeetbot.cc/api/v1/proxies | — | |
urlhttp://proxy.thebeholder.deno.net/set-token | — | |
urlhttp://thebeholder-proxy.deno.dev/set-token | — | |
urlhttps://enhanced.jeetbot.cc/ | — | |
urlhttps://ext-styles.jeetbot.cc/api/v1/proxies | — | |
urlhttps://proxy.morphilina.me/ | — | |
urlhttps://proxy.thebeholder.deno.net/ | — | |
urlhttps://thebeholder-proxy.deno.dev/ | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainalexue4.dev | — | |
domainmorphilina.me | — | |
domainjeetbot.cc | — | |
domainapi.jeetbot.cc | — | |
domainenhanced-1.jeetbot.cc | — | |
domainenhanced.jeetbot.cc | — | |
domainext-03.jeetbot.cc | — | |
domainext-styles.jeetbot.cc | — | |
domainimg.drisnya.online | — | |
domainproxy.morphilina.me | — | |
domainproxy.thebeholder.deno.net | — | |
domainthebeholder-proxy.deno.dev | — |
Threat ID: 6aa7c61b55bf5e2cf5e00f65
Added to database: 09/14/2026, 10:02:03 UTC
Last enriched: 09/14/2026, 10:20:52 UTC
Last updated: 09/15/2026, 03:10:00 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.