Researchers Find OAuth Token Exposure in Twitch Extension Used by 30K

Researchers found a Twitch extension used by 30,000 Chrome users transmitting OAuth tokens, potentially exposing authenticated account access.

Sep 15, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A Twitch browser extension used by roughly 30,000 Chrome users transmitted OAuth authentication tokens to infrastructure controlled by its developer, according to researchers at Socket.

The extension, Twitch Enhanced Viewer | JeetBot, is available through the official Chrome and Firefox stores and advertises features including higher-quality playback, ad blocking, and automatic channel-point collection.

Socket said the extension could extract OAuth tokens from authenticated Twitch sessions and attach them to requests sent through developer-controlled proxy servers, potentially giving the receiving infrastructure capabilities tied to users’ accounts.

According to Socket, the extension runs as intended and remains live in both stores as of publication.

How the OAuth token extraction operates

At first glance, neither extension looked like a fresh or suspicious upload. According to The Hacker News, the Chrome version, identified as pnhhdhhcadcjfckjhpmjneldiegbojfb, had been available since June 26, 2025, while the Firefox version, identified as twitchenhancedviewer@example.com, was published on July 7, 2025. 

The Chrome listing has about 30,000 users, while the Firefox version has 552, making the add-ons appear to be established Twitch tools rather than newly published extensions.

The extensions routed playlist requests through JeetBot-controlled proxy servers to provide features such as 1080p playback in restricted regions. The extension could access Twitch data inside the browser, recover the OAuth token associated with the user’s already-authenticated Twitch session, and then attach that token to requests sent through the proxy.

The security concern lies in the difference between the access required for the extension’s advertised features and the credentials it actually transmitted. According to Socket, having that token could allow read and write access to Twitch accounts, so exposing it gave the receiving infrastructure account-level capabilities beyond the video stream itself.

A notable detail in the implementation is that the extension had a separate workaround for 10 Russian channels that did not require forwarding the user’s OAuth token. The available reporting does not explain the reason for that exception, so it should not be attributed to a particular motive without supporting evidence.

Advertisement

Per The Hacker News, the developer disputed claims that the extension is malicious, noting that after recognizing the security implications of forwarding users’ OAuth tokens, they removed the feature in a previous version. However, tokens already transmitted are not automatically revoked just because the extension is updated.

Broader takeaway from this incident

For anyone who installed Twitch Enhanced Viewer | JeetBot, the immediate concern isn’t simply whether the extension is still live, but whether it transmitted an OAuth token while it was active. 

A valid token can allow someone to make requests as the account holder without knowing the user’s Twitch password, so updating or removing the extension addresses the source of the exposure but does not, by itself, invalidate credentials that may already have left the device.

Twitch users should therefore also revoke or refresh active sessions and review recent account activity for unfamiliar messages, chat activity, setting changes, or other actions they did not perform. 

Users who installed Twitch Enhanced Viewer | JeetBot should remove or update the extension, review their accounts for unfamiliar activity, and invalidate any authorization credentials that may have been exposed.

Simply deleting the extension or clearing browser data may not revoke an OAuth token that has already been transmitted. Users should follow Twitch’s official account-security guidance for revoking connected applications or active authorizations and consider changing their password if recommended.

But the incident also exposes a less obvious problem with relying on developer-submitted disclosures.

According to Socket, the extension’s declared data practices didn’t match what researchers observed, showing that privacy labels and data-collection declarations shouldn’t be trusted at face value. 

Users should still read those disclosures before installing an extension. However, they should also check the permissions it requests, what functionality actually requires those permissions, who operates the service behind it, and how often it is updated.

The incident also underscores a broader browser-extension security problem. Official store listings, long publishing histories, and developer-submitted privacy disclosures can create an appearance of trust without showing exactly what an extension does once installed.

Security teams should review the permissions granted to browser extensions, the external domains those extensions communicate with, and whether employees actually need the access being requested. For tools that can interact with authenticated sessions, credential exposure should be treated as a third-party access risk rather than simply a browser issue.

Advertisement

More news: Japan is investigating a breach of a government network that exposed internal data, adding to concerns over attacks targeting public-sector systems across the APAC region.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.