ADVERTISEMENT

Your Twitch login may be exposed: this one extension is leaking it to Russians

31,000 Twitch users may be at risk of account takeover.

Twitch

Mobile phone screen with Twitch app logo in a purple background

Paulina Okunytė
Paulina Okunytė Senior Journalist
September 15, 2026 4 min read
Key takeaways:

The extension does what it promises. But at what cost?

Token is sent to a Russian bot service

ADVERTISEMENT

Russian streamers' credentials are not harvested

Disclosures don't mention the token exfiltration

How to stay safe?

  • Anyone who has installed “Twitch Enhanced Viewer | JeetBot” should remove it from Chrome or Firefox immediately.
  • Users should then disconnect all active Twitch sessions and sign in again. This invalidates previously issued session tokens, including any that may have been forwarded by the extension.
  • Security teams should also consider blocking the infrastructure identified by Socket and checking endpoints for both the Chrome and Firefox extension IDs.
  • Extensions with broad permissions over authenticated services, combined with connections to third-party proxy infrastructure, should always be treated as a potential credential-exposure risk.

Twitch users' data allegedly on sale

  • Usernames
  • URLs
  • Emails
  • Legal names
  • Followers number
  • Status of account verification
Paulina Okunytė
Senior Journalist
ADVERTISEMENT