Executive Summary

In September 2026, a malicious Twitch browser extension called 'Twitch Enhanced Viewer | JeetBot' was discovered exposing OAuth tokens from nearly 31,000 users across Chrome and Firefox platforms. The extension, developed by HISHIMIRO/jeetbot.cc and operated by Cyprus-based developer Aleksandr Popov, routed users' authenticated Twitch sessions through operator-controlled proxy servers while claiming to provide ad-free viewing and region-unlocked content. The OAuth tokens were transmitted in cleartext as URL query parameters, enabling unauthorized access to users' chat, private messages, and account settings. Interestingly, the token forwarding mechanism excluded a hardcoded list of ten Russian streamer channels with large followings.

This incident highlights the growing threat of supply chain attacks targeting browser extensions and the critical importance of OAuth token security in modern web applications. As streaming platforms and social media continue to expand globally, malicious actors are increasingly exploiting trusted software distribution channels to harvest user credentials at scale.

Why This Matters Now

Browser extension supply chain attacks are surging as threat actors exploit users' trust in popular platforms. With over 31,000 victims exposed through a single malicious extension, this incident demonstrates how easily OAuth credentials can be harvested at scale through compromised browser add-ons.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The extension intercepted Twitch OAuth tokens and forwarded them as cleartext query parameters to operator-controlled proxy servers whenever users watched streams, except for a hardcoded list of ten Russian channels.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have reduced the blast radius of this browser extension compromise by constraining lateral access across cloud workloads and limiting the scope of token-based authentication abuse through segmented network controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: CNSF visibility would likely have detected anomalous network patterns from compromised endpoints attempting to reach cloud infrastructure, constraining the extension's ability to establish persistent communication channels with backend services.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust segmentation would likely have constrained the extension's ability to leverage stolen OAuth tokens across multiple cloud services and workloads, limiting the scope of privileged access even after credential compromise.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have limited the attacker's ability to move between different service tiers and user data repositories, constraining access to sensitive communication channels and account management functions.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls would likely have detected the proxy redirection patterns and constrained the extension's ability to establish covert communication channels through legitimate service endpoints across cloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely have constrained unauthorized data transmission to external proxy servers, reducing the volume of OAuth tokens successfully exfiltrated from cloud infrastructure to attacker-controlled endpoints.

Impact (Mitigations)

Residual impact would likely be constrained to a smaller subset of user accounts with limited cross-service access, as segmentation controls would have reduced the blast radius of token abuse across interconnected cloud workloads and services.

Impact at a Glance

Affected Business Functions

  • Content Streaming Services
  • User Authentication Systems
  • Digital Content Distribution
  • Social Media Platform Operations
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

OAuth tokens from approximately 31,000 Twitch users compromised, enabling unauthorized access to user chat, private whispers, and account settings. Tokens transmitted in cleartext to Russian-operated proxy servers.

Recommended Actions

  • Implement egress security controls to detect and block unauthorized OAuth token transmission in URL parameters to external proxy servers
  • Deploy multicloud visibility solutions to monitor suspicious browser extension traffic patterns and anomalous authentication flows
  • Establish zero trust segmentation to limit application-to-internet communications and prevent credential forwarding to unauthorized destinations
  • Enable threat detection capabilities to baseline normal authentication patterns and alert on OAuth token abuse or session anomalies
  • Configure cloud firewall policies with URL filtering to block known malicious proxy infrastructure and unauthorized credential forwarding endpoints

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image