JeetBot Leaks Twitch Sessions Through Browser Stores

Socket found a cross-store Twitch extension, Twitch Enhanced Viewer | JeetBot, live in Chrome and Firefox and forwarding users’ OAuth session tokens to a Russian bot service. The Chrome listing alone had about 30,000 users; the Firefox add-on was also still live. The extension rides the Twitch token already in the browser and sends it along when a user watches a channel, so the operator gets a working bearer token rather than a password. That means the account can be used immediately through Twitch’s own session, and removing the add-on does not end abuse if the token and session stay valid. For users and identity teams, the exposure sits at the session layer: any browser add-on that can read and relay logged-in tokens can hand an attacker direct account access. In this case, the lasting question is not whether the extension is gone, but whether Twitch OAuth grants and sessions have been invalidated on the accounts that used it.

Part of the PlainSec briefing for 2026-09-11

Every edition of this story: JeetBot Leaks Twitch Sessions Through Browser Stores

Sources