DEV Community

kchour96-dev
kchour96-dev

Posted on

JeetBot Twitch Extension Leaks OAuth Tokens for Over 31,000 Users Amidst Market Volatility

🔗 Live Dashboard: autonomous-portfolio-2026.live
📢 Telegram: t.me/AII2026futher

Today's Headlines

  • Malicious 'Twitch Enhanced Viewer | JeetBot' extension exposed live OAuth tokens from over 31,000 users across Chrome and Firefox.
  • Five new crypto projects, including iotex-core and Maskbook, are gaining traction on GitHub, signaling development activity.
  • The compromised Twitch OAuth tokens grant full account access (chat, whispers, settings), far exceeding necessary permissions for video playback.

⚠️ Threat [7/10]

Malicious 'Twitch Enhanced Viewer | JeetBot' extension exposed OAuth tokens for 31,000 users, indicating a significant supply-chain attack risk for browser extensions.

💡 Opportunity [6/10]

Despite security concerns, Bitcoin (BTC) is trading at $77,815 (+1.5% 24h), demonstrating resilience and potential for strategic entry points for long-term investors.

🪙 Tokens To Watch

PONS, LIT, LSK, ZEC, BTC

📊 Analysis

Despite a prevailing "BEARISH" sentiment in the broader crypto market, major assets are showing surprising resilience. Bitcoin (BTC) is currently trading at a robust $77,815, marking a 1.5% increase over the last 24 hours. Ethereum (ETH) also mirrors this upward trend at $2,512.51, reflecting a 1.5% gain, while Solana (SOL) leads with a 2.0% surge to $101.68. This minor positive movement suggests underlying strength or strategic buying activity, even as market participants grapple with perceived uncertainties. However, this bullish price action stands in stark contrast to significant security vulnerabilities emerging from the digital ecosystem, demanding investor vigilance and a balanced perspective on risks versus rewards.

A serious security threat has been uncovered with the "Twitch Enhanced Viewer | JeetBot" browser extension, which was secretly forwarding users' live Twitch OAuth session tokens to Russian proxy servers. Installed by over 31,000 users across Chrome and Firefox, this extension, marketed as an ad-blocker, covertly appended full account-scoped OAuth tokens as cleartext URL query parameters. This grants the operators complete control over affected Twitch accounts, enabling access to chat, whispers, and settings, far beyond any legitimate function for video playback. The fact that the listings remained live on official stores at the time of disclosure, and the exposure was not revealed in data-safety information, highlights a critical supply-chain vulnerability within popular browser extension ecosystems that all digital users must be aware of.

For crypto investors and digital users in Southeast Asia, this incident serves as a stark reminder of the pervasive digital risks within an increasingly interconnected online landscape. The region, known for its rapid adoption of digital technologies and emerging economies, often sees users relying heavily on browser extensions for enhanced online experiences. The lack of awareness regarding software supply chain security, coupled with the prevalence of less robust cybersecurity infrastructures in some areas, makes Southeast Asian users particularly vulnerable to such sophisticated token-leaking malware. Investors in the region must prioritize robust security practices, including multi-factor authentication and careful vetting of third-party tools, to protect their digital identities and, by extension, their crypto assets from compromised online accounts that could be exploited for phishing or credential stuffing attacks.

The malicious extension's evolution from direct token POSTing in earlier v4.x builds to inline forwarding in current v85.x builds demonstrates an adaptive threat model designed to evade detection. Initially, tokens were sent to dedicated collection endpoints, suggesting server-side storage, but this was later replaced by embedding the OAuth token directly into video-playlist requests as a URL query parameter. This method ensures the token is logged in cleartext by proxy servers, effectively making every video request a data exfiltration event. The exemption of ten hardcoded Russian-language streamer channels further points to a targeted and commercially motivated operation, likely aimed at boosting specific channels or manipulating viewership metrics while harvesting user data for broader illicit purposes.

Over the next 48 hours, the crypto market is likely to continue its precarious balance between positive price momentum and underlying bearish sentiment, influenced by macroeconomic factors and emerging security incidents. While major tokens like BTC, ETH, and SOL have shown short-term gains, the "JeetBot" incident underscores the continuous threat landscape. Users are strongly advised to immediately review their browser extensions, especially those interacting with sensitive accounts like Twitch, and remove any suspicious or unverified add-ons. Changing passwords and enabling two-factor authentication on all critical online services, particularly those linked to crypto exchanges, is paramount. Investors should also exercise caution when considering trending tokens like PONS, LIT, LSK, ZEC, and BTC, balancing potential gains with the heightened security risks highlighted by recent events.


AI-powered • Gemini + Groq + Free APIs. Updated every 2 hours.

Top comments (0)