JeetBot routed Twitch OAuth tokens to a Russian bot service via proxy servers
If you've installed a Twitch viewing extension promising ad-free streams or unlocked regional content, you'll want to check which one. Security researchers have traced a browser add-on called "Twitch Enhanced Viewer | JeetBot" to a token-leaking scheme affecting nearly 31,000 people across Chrome and Firefox.
Socket researcher Kush Pandya found that JeetBot's current build forwards each user's OAuth token as a plain query parameter during a network redirect to servers run by a commercial bot operator.
That token acts as a bearer credential, meaning whoever holds it can read chat, send whispers, and touch account settings without needing a password or two-factor code.
Ten different channels, primarily Russian-speaking streamers, each with up to 1.1 million followers, have been programmed into an allowlist that would stop forwarding viewers’ tokens. All other channels, apart from those included in the allowlist, were having their live viewing sessions directed through the operator’s proxy.
JeetBot is promoted as a bot for Twitch, Kick, and VK Live channels with more than 26,000 active streamers and a billion messages processed. At the bottom of its website, JeetBot is attributed to Aleksandr Popov, a Cyprus-based developer who refers to it as a side project on LinkedIn.
The latest Firefox build 85.8.7 released by the developer doesn't send any tokens to the proxy servers, but a compatible update for Chrome is pending approval in the store.
Any person using the old version continues to send their token to the servers until they update the browser, and it is stated that neither updating nor disabling the plugin can reverse the process of collecting tokens.