A malicious browser extension distributed through official stores leaks Twitch OAuth session tokens from users to external proxy infrastructure. The extension, “Twitch Enhanced Viewer | JeetBot,” is available on both Google Chrome Web Store and Mozilla Firefox Add-ons.

Across reports, the extension is described as sending the tokens to a bot service listed as HISHIMIRO/jeetbot.cc, with activity routed through proxy servers operated by a Russian commercial bot provider. Bleeping Computer and The Hacker News both characterize the behavior as a security breach that can allow attackers to reuse OAuth tokens and potentially access affected Twitch accounts.

The outlets focus on the same core technical issue—token exposure—and the approximate scale of impact, reported as nearly 31,000 users or around 30,000 installs. While details on investigation methods and attribution wording differ slightly, both accounts point to the extension’s cross-store availability and its developer attribution as central to the incident’s identification. Both also note that the extension remains accessible through the stores, raising concerns about how long the malicious code remained in circulation.