{
  "id": 7382064,
  "title": "31,000 Twitch users hit by malicious browser extension — OAuth tokens leaked via Russian proxy network",
  "url": "https://urgent.news/2026/09/14/31-000-twitch-users-hit-by-malicious-browser-extension-oauth-tokens",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-14T19:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/31-000-twitch-users-hit-by-malicious-browser-extension-oauth-tokens-leaked-via-russian-proxy-network"
  },
  "original_language": "en",
  "account": "A malicious browser extension for Twitch, \"Twitch Enhanced Viewer | JeeBot,\" has compromised the OAuth tokens of approximately 31,000 users. The extension, found on both Chrome and Firefox, was designed to harvest these tokens via Russian proxy servers. It was advertised as a tool for streamers and viewers, offering features like clearer streaming, 2K viewing, ad blocking, and even an AI bot for easier interaction. However, the developers inadvertently placed users' OAuth tokens in the proxy server's request logs. After being exposed, the developer released an update to fix the issue, but it appears that the tokens were being forwarded to the proxies, even if only for 10 Russian streamer channels. Security researchers advise users to revoke their exposed Twitch tokens for safety measures.",
  "summary": "The extension has since been updated to remove the OAuth exfil.",
  "key_points": [
    "Approximately 31,000 Twitch users' OAuth tokens compromised",
    "Malicious browser extension harvested tokens via Russian proxies",
    "Developer released update, but tokens still forwarded to proxies"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}