Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service

Published September 11, 2026

A fake Twitch extension called JeetBot secretly sends your Twitch login token to a Russian bot service. This lets the service control your account and watch streams on your behalf, even if you don't want it.

Report priority
Medium

How it works

  • The fake Twitch extension 'Twitch Enhanced Viewer | JeetBot' claims to block ads and improve video quality.
  • Instead, it sends your Twitch login token to a Russian bot service every time you watch a stream.
  • The token lets the service act as you on Twitch, even if you don't know it.
  • Older versions of the extension sent your token directly to the bot service's servers. the current version hide the token in a hidden web request when you watch a stream.

What to do

Check your installed extensions in Chrome or Firefox to see if it's listed. If you see it, remove it immediately.

Remove the extension from Chrome or Firefox now. In Chrome, go to Settings > Extensions and delete 'Twitch Enhanced Viewer | JeetBot'. In Firefox, go to Add-ons and remove it. Do not reinstall it. If you suspect your Twitch account was compromised, change your password and enable two-factor authentication. Watch for unusual activity, like streams you didn't watch or messages you didn't send.

Technical details

A malicious browser extension called "Twitch Enhanced Viewer | JeetBot" (Chrome extension ID pnhhdhhcadcjfckjhpmjneldiegbojfb, Firefox Add-ons sample email) steals users' Twitch OAuth tokens by embedding them in network requests sent to a Russian-operated bot service. The extension, with over 30,000 Chrome users and 552 Firefox users, forwards tokens via query parameters (&auth=) in redirects to proxy servers for versions 85.x, while older builds (e.g., 4.8 from January 2026) directly POSTed tokens to a dedicated endpoint on the operator's infrastructure, including backups on deno.dev and deno.net. The attacker, a commercial bot SaaS provider for Twitch, Kick, and VK-Live, gains authenticated access to users' sessions, enabling unauthorized control of their accounts and streams. The extension's advertised features, ad blocking, forced 1080p playback, and region unlocking, are legitimate but serve as a cover for the token exfiltration.

References