- Socket found Twitch extension JeeBot harvesting OAuth tokens via proxy servers
- Tokens excluded only for 10 Russian streamer channels, suggesting deliberate design
- Developer issued fixes, but users should revoke exposed tokens for safety
A browser extension for Twitch was harvesting people’s OAuth tokens and sending them to a Russian-owned server. The move was deliberate, but whether or not it was malicious is not that easily determined.
Security researchers Socket recently found an extension for both Chrome and Firefox, called “Twitch Enhanced Viewer | JeeBot”. It has roughly 30,000 users on Chrome, and some 600 on Firefox.
On the Chrome Web Store, it is advertised as a “modern tool for streamers and viewers who value quality, convenience, and control.” Apparently, it makes streaming and viewing clearer, allows viewing content in 2K, hides banner ads and unwanted elements, and even offers an AI bot to make it easier to interact with the stream.
Latest Videos FromTechRadar
Hardcoded exemptions
According to the researchers, the extension is designed to retrieve Twitch’s video stream playlists through its own proxy servers. However, instead of simply forwarding the requests, the extension also attached users’ OAuth tokens, and since they were placed in the URL, the token also ended up in the proxy server’s request logs.
After being called out for it, the extension’s developer (HISHIMIRO/jeetbot.cc) released a new version 85.8.7 (for Firefox, the Chrome one is currently under review) which apparently fixes this flaw: when playlists are retrieved, the user’s OAuth token is no longer sent to the proxies. It would seem like this was an honest mistake that was remedied upon responsible disclosure. However, here is what Socket had to say about the way the tokens were being retrieved:
“Current builds (v85.x) forward the token inline as an &auth= query parameter on a network-layer redirect to the operator’s proxy,” Socket explained. “The token is forwarded for every channel the user watches, except a hardcoded allowlist of ten Russian streamer channels, whose sessions are exempted from forwarding.”
If there was a list of 10 Russian streamer channels who were exempt from OAuth token retrieval, it’s safe to assume that the developer knew very well what they were doing.
It is good that the extensions were upgraded, but if you are using it, you should also revoke the exposed Twitch token, to be on the safe side.
Via The Hacker News
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

