A malicious Twitch browser extension has exposed OAuth tokens for nearly 31,000 users to proxy servers controlled by a Russian commercial bot service. The extension, known as "Twitch Enhanced Viewer | JeetBot," is listed under the developer HISHIMIRO/jeetbot.cc and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store: - Chrome - pnhhdhhcadcjfckjhpmjneldiegbojfb - 30,000 users (Published on June 26, 2025) - Firefox - twitchenhancedviewer@example.com - 604 users (Published on July 7, 2025) Both extensions are still accessible for download as of the current write-up.
The extension listing description emphasizes: "JeetBot is a contemporary tool designed for streamers and viewers who value quality, convenience, and control." It also highlights that "JeetBot expands Twitch's capabilities: 1080p stream for regions with limitations." Current builds (v85.x) forward the token inline as an &auth= query parameter on a network-layer redirect to the operator's proxy.
The extension claims to offer an ad-free experience and serve region-unlocked content by routing Twitch's video-playlist requests to "usher.ttvnw[. ]net" through operator-controlled proxy servers along with the user's OAuth token as an "&auth=" query parameter. Earlier versions, such as v4.x (e.g., version 4.8, January 2026), expanded on this by POSTing the token to a dedicated set-token endpoint on the operator host, with additional backups on deno.dev and deno.net.
An equivalent Chrome version is currently being reviewed.












