Malicious Twitch Extension Siphoned Login Tokens From 31,000 Viewers

A browser add-on marketed as a Twitch viewer tool quietly forwarded OAuth tokens to servers linked to a Russian bot-for-hire service.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Full-frame edge-to-edge photoreal overhead shot of a dark desk with a laptop screen showing an abstract browser extensions management interface, glowing slightl
Share

Key points

  • A browser extension called "Twitch Enhanced Viewer | JeetBot" leaked OAuth login tokens for close to 31,000 Twitch users.
  • Tokens were sent to proxy servers run by a Russian commercial bot service, according to The Hacker News.
  • The extension appeared on both the Chrome Web Store and the Firefox Add-Ons store under the developer name HISHIMIRO / jeetbot.cc.
  • OAuth tokens work like temporary house keys: whoever holds one can act as the user without a password.
  • Anyone who installed the extension should remove it, disconnect it from their Twitch account, and force-log-out of all sessions.

A browser add-on that promised to make Twitch nicer to watch was quietly stealing the keys to viewers' accounts.

The extension is called "Twitch Enhanced Viewer | JeetBot." Published on the Chrome Web Store and the Firefox Add-Ons store under the developer name HISHIMIRO, linked to jeetbot.cc, it collected OAuth tokens belonging to nearly 31,000 Twitch users and pushed them to proxy servers tied to a Russian commercial bot service.

An OAuth token is a short-lived credential a site hands your browser after you log in: a temporary key that says "this browser is you" so you don't have to type your password on every click. If someone else gets that key, they can walk into your account without the password or a two-factor code.

That's what appears to have happened here at scale.

Who is behind it?

The developer name on both stores is HISHIMIRO, with jeetbot.cc as the associated site. Stolen tokens were routed through proxy servers operated by a Russian company that sells bot services commercially, the kind of outfit streamers and marketers pay to inflate view counts and chat activity.

Attribution beyond that is thin. There's no public link to a named state-aligned cluster such as those tracked by Mandiant or Microsoft, and nothing in the reporting supports calling this espionage. On current evidence this looks like a criminal monetisation play: harvest live Twitch sessions, feed them into a view-botting and engagement-fraud pipeline, sell the output.

Capability isn't the same as intent. The same token theft could be used to hijack partner accounts or push scam links in a streamer's name. The 31,000 figure is the pool of exposed users, not a count of confirmed account takeovers.

How did a malicious extension end up in both stores?

Browser extension review at Google and Mozilla is largely automated, with human spot-checks. A tool that reads the page you're on and talks to a remote server isn't, by itself, suspicious: that's what most extensions do. The malicious behaviour sits inside otherwise normal-looking traffic to a viewer-enhancement tool.

This is a recurring pattern. Extensions ship clean, build an install base, then either update with hostile code or were hostile from day one behind a benign feature set. Twitch's own login flow wasn't broken; the add-on simply read what the logged-in user could already see. Our 20 August report on 40 fake Firefox wallet extensions draining crypto from users shows the same store-based delivery model used against a different audience.

At time of writing there's no public confirmation from Google or Mozilla on takedown status, nor a full victim list from Twitch.

What should viewers and streamers do now?

Remove the extension if you have it, then treat your Twitch account as if the password was posted online.

In Twitch's Security and Privacy settings, disconnect all other sessions to invalidate stolen tokens. Reset your password, turn on two-factor authentication if you haven't already, and revoke any unfamiliar connected apps. Streamers should also check for stream key resets and review recent moderator actions and payout details.

Be wary of any Twitch extension whose selling point is boosting views or follower counts. That category attracts exactly the kind of developer who has an incentive to steal sessions.

Detail Value
Extension name Twitch Enhanced Viewer | JeetBot
Developer listed HISHIMIRO / jeetbot.cc
Stores Chrome Web Store, Firefox Add-Ons
Users exposed ~31,000
Data leaked Twitch OAuth tokens
Destination Proxy servers of a Russian bot service

The theft itself isn't the most interesting part. Tokens flowing straight into a commercial view-botting operation suggests the whole point was feedstock for engagement fraud, a quieter and more profitable game than smash-and-grab account takeover. Watch for more of these.

© 2026 Threat Vectr