Tendvane

← All articles

SecuritySeptember 14, 2026

A Twitch add-on with 30,000 users was quietly posting login tokens to a Russian bot service

Thirty thousand people installed it to get rid of Twitch ads. It was also mailing their login tokens to somebody else.

The extension is called Twitch Enhanced Viewer | JeetBot and it has sat on the Chrome Web Store since June 2025, with a few hundred more users on Firefox. On the surface it does what Twitch viewers actually want: strips ads, forces 1080p where stream quality is capped, collects channel points on its own. Researchers at Socket took it apart and found the rest. Every time you watched a stream, the add-on grabbed your Twitch OAuth session token and bolted it onto a redirect as a plain &auth= parameter, routing it through proxy servers belonging to a Russian commercial bot service, where it lands in the request logs in clear text.

That token is not a password. It is better than one, from an attacker's point of view. It opens your chat, your private whispers and your account settings, and it does not care whether you have two-factor switched on, because you already passed that. Socket's Kush Pandya turned up one more detail worth sitting with: ten Russian-language channels were written into an exemption list, so watching those leaked nothing. Somebody made that choice deliberately.

The developer, who gives his name as Aleksandr Popov, described the whole thing as "an oversight" and has shipped a Firefox build, 85.8.7, with the forwarding stripped out; a Chrome version is waiting on review. That fixes nothing for anyone already affected, because a token that has leaked stays valid until you kill it. Remove the extension, then open Twitch settings and disconnect all sessions before signing back in. If you are not certain what else has crept into your browser over the years, Tendvane's safety check lists the extensions and startup entries it finds, including the ones you do not remember agreeing to.

Sources

Download Tendvane