MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-14 · via BleepingComputer

Twitch add-on with 30,000 users sends login credentials to external service

Image via BleepingComputer
Image via BleepingComputer

A browser extension for Twitch, available in official Chrome and Firefox stores, has been found to transmit users' OAuth session tokens to a commercial bot service. Security researchers discovered that the extension appends the token as a URL parameter in proxy requests, leaving it exposed in server logs. The developer's privacy disclosure claims no data collection, contradicting the observed behavior.

Expanded Detail

The extension, listed in both major browser stores, routes Twitch video requests through JeetBot’s proxy servers. Socket’s analysis found the OAuth token is placed in the URL query string, meaning it appears in server logs in plaintext. Earlier versions used even more direct credential capture, and the developer’s own Firefox description admitted token transmission for higher-resolution streaming. The Chrome privacy disclosure, however, states no data collection, a direct contradiction.

The token is sent for every channel watched except ten hardcoded Russian-language streams. With over 30,000 installs, the exposure is significant. Socket advises users to remove the extension, log out of Twitch, and re-authenticate to invalidate any leaked tokens. The extension remained available in both stores at publication time, and JeetBot did not respond to requests for comment.

Context

This incident could erode trust in browser extensions, especially those promising convenience features like ad-blocking or region bypass. Users who installed it may face account hijacking, unauthorized purchases, or identity exposure if tokens are misused. The broader impact may push platform owners like Google and Mozilla to tighten review processes, but the burden often falls on users to verify permissions. Such disclosures could also prompt more scrutiny of third-party tools in streaming communities, where convenience often outweighs security caution.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Mantax Otax malware combines ransomware and spyware to target older Android devices · Cybersecurity
Tens of thousands of internet-facing Plex servers still lack fixes for known security bugs · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Twitch extension with 30K installs exposes users’ OAuth tokens.” Browse more stories.