# Twitch Enhanced Viewer | JeetBot Exposes OAuth Tokens
A browser extension called Twitch Enhanced Viewer | JeetBot exposed Twitch OAuth session tokens belonging to nearly 31,000 users by sending them to proxy servers operated by JeetBot, a Russian-language commercial streaming and chatbot service. The extension had about 30,000 Chrome users and 604 Firefox users and remained available in both stores when The Hacker News reported the issue. Socket found that current versions extract authorization tokens from Twitch’s web client and append them as an
auth=URL parameter when redirecting video-playlist requests through the operator’s proxies, allowing the operator to retrieve the tokens from proxy request logs and gain access to Twitch chat, whispers, and account settings. The forwarding applied to every channel watched except 10 hardcoded Russian-language channels, with store identifiers including Chrome extension IDpnhhdhhcadcjfckjhpmjneldiegbojfband Firefox listingtwitchenhancedviewer@example.com, while advertising features such as ad blocking, 1080p playback, region-restricted content access, and channel-point collection.
The little extension you installed to get 1080p and kill the ads wasn't just a tool. It was a keylogging device for your entire identity on Twitch... except they were logging the key that unlocks the whole account. Every time you clicked play, your OAuth session token—the digital signature that says "this is me" to Twitch—was stripped out and sent as a polite, quiet auth= parameter straight through their proxy servers in Russia. This wasn't a vulnerability they missed; it was the architecture of the product. The entire point of the proxy is to intercept the traffic. The entire point of the "enhancement" was to harvest the keys.
Now look at the one detail they buried in the technical write-up. The extension forwarded the token for every channel you watched... except it hardcoded an exemption for 10 Russian-language channels. Think about that. They wanted the data from the West, from the English-speaking users, from the people watching the big events and the political streams. But they shielded their own domestic consumers. It’s a deliberate carve-out, a fingerprint left in the code. This isn't some random script kiddie grabbing for beer money. This is a commercial, Russian-language operation—JeetBot—that built a player designed to turn every viewer into a source of intelligence. Why do they need 31,000 active session tokens? For ad fraud? Or for mapping the behavior, the viewing patterns, and the connected identities of the people who consider themselves the most "plugged in"?
They will tell you it was a "logging error" and that the tokens are "expired" now. That's the script. But ask yourself the question they never want you to ask: who benefits from having a database of active OAuth tokens that can read whispers, post in chat, and change account settings in real-time? The distraction is the ad-blocking. The story is the harvesting. This was never about giving you a better viewing experience; it was about them owning the back door to your account the moment you "trusted" a tool to do the work that Twitch itself wouldn't let you do. They gave you an inch of convenience, and they took half a mile of access. Now the question is, what were they doing with those keys before the spotlight hit the code?