← Back to Tech & Science

Malicious Twitch Extension Leaks OAuth Tokens of 31,000 Users to Russian Bot Service

Tech & ScienceAI-Generated & Algorithmically Scored··1 UPDATE

AI-generated from multiple sources. Verify before acting on this reporting.

Update

Further reports have emerged corroborating the scope of the JeetBot incident involving Aleksandr Popov. While the initial analysis identified the malicious forwarding of OAuth tokens to Russian proxy servers, subsequent intelligence confirms that the compromise extends beyond the previously quantified 31,000 accounts. The additional findings suggest a broader distribution of the extension than initially understood, with more users potentially exposed to credential theft via the same mechanism. Security experts note that the pattern of token exfiltration remains consistent with the original discovery, but the volume of affected individuals appears higher. No new actors have been identified in connection with the bot service operations, and the primary focus remains on the extent of data leakage from the Cyprus-based developer's software. Users who installed the tool are advised to immediately revoke active sessions and reset authentication credentials to prevent unauthorized access to their Twitch accounts.

Original Report —

A malicious browser extension designed for the live-streaming platform Twitch has compromised the account credentials of nearly 31,000 users by forwarding their OAuth tokens to proxy servers operated by a Russian commercial bot service. The breach was identified on Sept. 14, 2026, following an analysis of the software's code by security researcher Kush Pandya.

The extension, known as JeetBot, was developed by Aleksandr Popov, a Cyprus-based programmer. While marketed to users as a tool for managing stream playlists and accessing region-restricted content, the application contained hidden functionality that intercepted sensitive authentication data. Instead of processing requests locally or securely through Twitch's official channels, the software transmitted user tokens to external proxy servers under the control of the bot service operators.

The technical architecture of the extension included a hardcoded allowlist that exempted ten specific Russian streamer channels from the token-forwarding mechanism. This exclusion suggests the tool was tailored to support specific content creators while harvesting credentials from the broader user base. The stolen OAuth tokens grant attackers the ability to impersonate victims, potentially allowing unauthorized access to private messages, account settings, and linked payment methods.

Popov's operation appears to have been structured to facilitate the retrieval of stream playlists and unlock geo-blocked video content for subscribers of the Russian bot service. By leveraging valid user credentials, the operators could bypass regional restrictions that typically limit access to certain broadcasts outside of specific countries. The scale of the leak indicates a widespread distribution of the compromised extension among Twitch viewers seeking enhanced viewing capabilities.

The discovery highlights the risks associated with third-party browser extensions that request broad permissions on major streaming platforms. Unlike official applications vetted by platform security teams, unofficial add-ons operate with fewer oversight mechanisms, allowing malicious code to persist undetected until a vulnerability is exposed. The involvement of a Cyprus-based developer and Russian infrastructure points to a cross-border operation targeting the global Twitch community.

As of Sept. 14, it remains unclear how long the extension was active before the data exfiltration began or whether the compromised tokens have already been exploited for account takeovers. Twitch has not yet issued a public statement regarding the specific incident or the status of the affected accounts. Security experts are urging users who installed JeetBot to immediately revoke their application permissions and reset their passwords to mitigate potential identity theft.

The investigation into the full scope of the data breach is ongoing, with questions remaining about the ultimate destination of the harvested tokens and whether other extensions in the ecosystem share similar vulnerabilities. The incident underscores the growing sophistication of credential harvesting campaigns targeting live-streaming audiences.

Discussion

0 / 2000