A Twitch viewer add-on slipped 31,000 session tokens to a bot service

A viewer add-on with tens of thousands of installs sent live Twitch session tokens to a commercial bot operator.

CSBadmin
2 Min Read

A cross-store browser extension that promises smoother Twitch viewing has been quietly shipping viewers’ login tokens to servers run by a commercial bot service.

The add-on, billed as “Twitch Enhanced Viewer | JeetBot,” claims more than 30,000 installs on the Chrome Web Store and about 604 on Firefox. Socket researcher Kush Pandya found that current builds append the viewer’s Twitch OAuth token to a redirect that points at the operator’s proxy.

An OAuth token works like a bearer credential: whoever holds it can post in chat, read and send private whispers, and change account settings without a password or a second factor. Because the token rides in a URL query string, it also lands in the proxy’s request logs in cleartext.

Socket said roughly 31,000 users across both stores route live session tokens through the operator’s infrastructure. The behavior is not disclosed in either listing.

One oddity stood out: the forwarding skips ten hardcoded Twitch channels, nearly all of them Russian-language streamers. The developer, Aleksandr Popov, told The Hacker News the exemption was a playback workaround for viewers who could not open those channels from outside Russia, and that the list is user-adjustable.

Popov said the token handling was an oversight rather than malicious intent, and that version 85.8.7 of the Firefox build no longer sends tokens to his proxies. A matching Chrome update is awaiting store review. He also warned that updating or disabling the extension does not revoke tokens already transmitted.

Users who installed either build should update to 85.8.7 or later, and treat their Twitch sessions as compromised.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.