Executive Summary
In September 2026, security researchers discovered that the 'Twitch Enhanced Viewer | JeetBot' browser extension, installed by over 30,000 users across Chrome and Firefox stores, was secretly harvesting users' OAuth authentication tokens. The extension, marketed as a legitimate Twitch enhancement tool for ad-blocking and quality improvements, redirected users' streaming requests through Russian-operated proxy servers while embedding authentication credentials in URL parameters, making them easily accessible in server logs. This supply-chain attack demonstrates the persistent risk of malicious browser extensions infiltrating official app stores despite security reviews.
This incident highlights the growing trend of credential theft through seemingly legitimate browser extensions, coinciding with increased regulatory scrutiny of third-party software supply chains and the need for enhanced OAuth token security practices.
Why This Matters Now
Browser extensions continue to bypass platform security reviews while harvesting sensitive authentication data, with over 30,000 users affected in this case alone, highlighting urgent gaps in third-party software vetting and OAuth token protection.
Attack Path Analysis
The Twitch Enhanced Viewer | JeetBot browser extension with 30K installs compromised user OAuth tokens by intercepting authorization headers and transmitting them to Russian-operated proxy servers. The malicious extension established persistence through legitimate app stores, escalated access by capturing session tokens, maintained command and control through proxy infrastructure, and exfiltrated credentials via cleartext URL parameters in server logs for potential account takeover and unauthorized API access.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Malicious browser extension installed through legitimate Chrome Web Store and Firefox Add-ons store, masquerading as legitimate Twitch enhancement tool with ad blocking and HD streaming features
MITRE ATT&CK® Techniques
Steal Web Session Cookie
Credentials from Web Browsers
Exfiltration to Cloud Storage
Trusted Relationship
Spearphishing Link
Match Legitimate Name or Location
Web Portal Capture
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Authentication Credentials Management
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – Third-party Risk Management
Control ID: Article 28
CISA ZTMM 2.0 – Asset Management and Authorization
Control ID: ZT.AM-03
NIS2 Directive – Supply Chain Security
Control ID: Article 21.2(e)
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Entertainment/Movie Production
Twitch extension supply-chain attack exposing OAuth tokens threatens streaming platforms, requiring enhanced egress security and zero trust segmentation for creator protection.
Computer Software/Engineering
Browser extension credential theft demonstrates supply-chain vulnerabilities requiring encrypted traffic controls, anomaly detection, and secure development practices for software vendors.
Gaming/Casinos
OAuth token exposure in gaming platforms creates data exfiltration risks, necessitating multicloud visibility controls and threat detection for user session protection.
Marketing/Advertising/Sales
Streaming platform security breaches impact digital marketing channels, requiring egress policy enforcement and east-west traffic security for advertising campaign protection.
Sources
- Twitch extension with 30K installs exposes users’ OAuth tokenshttps://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/Verified
- Malicious Twitch Browser Extension Steals OAuth Tokenshttps://socket.dev/blog/malicious-twitch-browser-extensionVerified
- Chrome Web Store - Twitch Enhanced Viewer | JeetBothttps://chromewebstore.google.com/
- Firefox Add-ons - Twitch Enhanced Viewer | JeetBothttps://addons.mozilla.org/
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this browser extension attack by constraining lateral movement between cloud workloads and limiting egress pathways for token exfiltration to Russian proxy servers.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud workload segmentation would likely limit the extension's ability to reach internal services or databases where stolen tokens might be processed or stored
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls would likely restrict the compromised session's ability to access privileged cloud services or escalate permissions within segmented workloads
Control: East-West Traffic Security
Mitigation: Microsegmentation between application workloads would likely reduce the attacker's ability to move between cloud services using compromised tokens or session credentials
Control: Multicloud Visibility & Control
Mitigation: Network visibility controls would likely detect and constrain suspicious outbound communication patterns to external proxy infrastructure across cloud environments
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely restrict unauthorized data transmission pathways to external proxy servers, limiting token exfiltration from cloud workloads
Even with compromised tokens, the attacker's access to backend cloud services would remain constrained by segmentation policies, limiting the scope of account manipulation or data access
Impact at a Glance
Affected Business Functions
- User Authentication Services
- Content Streaming Platform
- Digital Content Access Control
- Third-party Integration Management
Estimated downtime: N/A
Estimated loss: N/A
OAuth session tokens for approximately 30,000 Twitch users exposed to unauthorized third-party servers operated by JeetBot service. Tokens transmitted in cleartext through proxy server request logs, potentially enabling account takeover and unauthorized access to user streaming accounts.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent browser extensions from accessing sensitive authentication tokens and enforce least privilege access controls
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized transmission of OAuth tokens to external proxy servers
- • Enable Multicloud Visibility & Control to monitor suspicious automation patterns and anomalous interactions with third-party services
- • Utilize Cloud Firewall (ACF) with URL filtering to block communications with known malicious proxy infrastructure and unauthorized destinations
- • Establish Threat Detection & Anomaly Response capabilities to identify credential exfiltration patterns and baseline normal authentication behaviors



