The Chrome Web Store listing for Twitch Enhanced Viewer
At a Glance
Security researchers discovered a malicious Twitch extension that leaked active authentication tokens from more than 31,000 users. The add-on operated on official browser web stores for months. It sent live credentials directly to proxy servers linked to an external bot provider.
| Malware Family | Twitch Enhanced Viewer (JeetBot) |
|---|---|
| Threat Actor | JeetBot (Suspected Russian commercial bot service operator) |
| Target or Victims | Over 31,000 Twitch and browser users |
| Delivery Vector | Chrome Web Store and Firefox Add-ons marketplace listings |
| Key Capabilities | Token interception, proxy redirection, and cleartext credential logging |
| Source | Socket Threat Research Team and browser marketplace telemetry |
TL;DR
A popular browser add-on marketed as a video quality booster actively captures user session credentials. The tool forwards authorization tokens to third-party proxy servers without user consent. Consequently, thousands of streaming accounts remain exposed to account hijacking.
Delivery Mechanism Across Official Stores
The developers distributed the add-on through both the Chrome Web Store and Firefox Add-ons repositories. More than 30,000 people installed the Chrome package, while over 500 users installed the Firefox version. The listing promised quality-of-life improvements such as blocking video advertisements and unlocking high-resolution streams.
In reality, these practical features served as a lure. Users installed the software to bypass regional stream restrictions. However, the software secretly abused browser permissions to access account data. According to researchers, “The operator is a commercial Twitch, Kick, and VK-Live bot SaaS that has broad Twitch host permissions and relays live authenticated sessions through its own infrastructure.”
The Extension Infection Chain
The infection begins immediately after installation in the browser. First, the script monitors browser tabs for active streaming sessions. When a victim loads the video platform, background scripts extract the active authorization header.
Next, the extension intercepts media playlist requests. Instead of contacting official content servers directly, the add-on routes traffic through remote proxy systems. During this step, the script attaches the user authentication token directly to the web request URL. This design ensures that every proxied stream request transmits the user credentials.
Command and Control and Data Exfiltration
The extension transmits stolen bearer tokens to external proxy servers located across European hosting providers. Because the code places credentials in URL parameters, proxy servers write these sensitive tokens directly into cleartext access logs. Anyone with access to those logs can hijack victim accounts.
Interestingly, the developers included an allowlist of specific channels. The software exempts ten popular Russian streamer channels from this credential harvesting routine. For all other channels, the malicious Twitch extension forwards login tokens across the network.
Earlier versions used a different communication design. In early 2026 builds, the add-on transmitted tokens directly to dedicated collection endpoints via explicit background requests. Security analysts detail these mechanisms in the Socket report on the extension. This malicious Twitch extension token theft allows attackers to send chat messages, read private whispers, and spend account points.
Defense and Detection Guidance
Users must remove the add-on from Chrome and Firefox immediately. After uninstalling the software, users should visit their account security settings. They must disconnect all active sessions to invalidate compromised authorization tokens.
Security teams should audit endpoint browsers for unauthorized add-ons. Administrators can block connections to known proxy servers operated by the bot service. Furthermore, enterprise networks should restrict browser permissions that allow traffic rerouting on authenticated platforms. Reviewing web extensions regularly remains critical to prevent unauthorized access.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!