Urgent.News

What's breaking now, across thousands of outlets.

Tech

JeetBot extension routes Twitch tokens to bot servers

A browser extension used by nearly 31,000 Twitch viewers has been found forwarding live OAuth session tokens to proxy infrastructure controlled by the operator of a Russian-language commercial bot service, exposing credentials that can grant access to account functions without requiring passwords or two-factor authentication. Security company Socket said the extension, “Twitch Enhanced Viewer |…

A browser extension with nearly 31,000 users on Twitch has been discovered forwarding live OAuth session tokens to proxy infrastructure controlled by a Russian-language commercial bot service. This exposes credentials that can grant access to account functions without needing passwords or two-factor authentication. The extension, "Twitch Enhanced Viewer | JeetBot," was available through both the Chrome Web Store and Mozilla’s Firefox Add-ons marketplace when its security flaws were discovered on September 11.

The extension, marketed as a viewing enhancement tool, blocks ads, provides higher-quality streams, bypasses regional restrictions, and automatically collects channel points. However, security analysis revealed it redirects Twitch video-playlist requests through operator-controlled proxy servers and appends the viewer’s OAuth credential to the redirected request.

This token, not limited to video playback, is used to authorize actions permitted by its scope. Researchers found it could be written into proxy request logs in clear text and was stripped for a hardcoded list of 10 Russian-language Twitch channels while forwarded for other watched channels. The forwarding mechanism was traced across version 85.x releases, and earlier 4.x builds sent captured tokens directly to a "set-token" endpoint operated by the same service.

This exposes potential capabilities such as participating in chat, accessing whispers, and interacting with account features depending on the granted token scope. Twitch's OAuth documentation warns that user access tokens should be protected like passwords, and Socket advised affected users to remove the extension and disconnect active Twitch sessions.

Despite the findings, the Firefox listing remained accessible with roughly 600 users, showing the extension was still publicly obtainable after the disclosure.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in Tech

Human operator executes Marimo cloud pivot in eight seconds

A skilled human attacker exploited a critical Marimo notebook flaw and moved from an exposed WebSocket session to authenticated access on an SSH bastion host in eight seconds, Sysdig’s Threat Research…

  • Human attacker exploited Marimo notebook platform vulnerability in 8 seconds
  • Operator used Python toolkit, manual debugging and deliberate pacing
  • CVE-2026-39987 vulnerability disclosed April 8, rated critical

More from Tuesday 15 September →