Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Ravie LakshmananSep 14, 2026Malware / Browser Security A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store – Chrome – pnhhdhhcadcjfckjhpmjneldiegbojfb – 30,000 users (Published on June 26, 2025) Firefox – twitchenhancedviewer@example.com – 604 users (Published on July 7, 2025) Both extensions are still available for download as of writing. The extension listing description states: "JeetBot is a modern tool for streamers and viewers who…
Original source: thehackernews.com