When Convenience Costs Your Credentials: The JeeBot Twitch Extension Incident

A popular browser extension for Twitch was recently caught harvesting OAuth tokens through a proxy network, proving that convenience often comes with a hidden security tax....

Feed
September 14, 2026
When Convenience Costs Your Credentials: The JeeBot Twitch Extension Incident


We live in an era of browser extension bloat. People install dozens of small utilities to block ads, tweak video players, or inject AI chatbots into their daily web browsing, rarely thinking about the immense privilege those extensions hold. A browser extension isn't just a script; it's a localized piece of software with the keys to your digital kingdom. That reality hit home for over 31,000 users who installed a popular Chrome and Firefox utility called JeeBot, advertised as an all-in-one quality-of-life upgrade for Twitch viewers.

Recently, security researchers at Socket uncovered that this benign-looking tool was quietly siphoning user OAuth tokens; and, routing them directly to a Russian proxy network. When fetching video stream playlists, guaranteeing they'd be captured in server request logs. The mechanics of the leak were remarkably brazen: the extension appended sensitive login tokens frankly into URL query factors. When caught, the developer scrambled to push an update and claimed innocence, pointing to a standard bug fix. But engineering reality tells a other story.

What separates an honest coding mistake from intentional data harvesting is usually found in the details of the codebase. Plus, truth is, in this case, the extension's routing logic included a hardcoded allowlist of ten specific Russian streamer channels that were completely exempt from token forwarding. Accidentally, if you're leaking session tokens, you leak them indiscriminately. You aren't debugging, you're operating a targeted data collection pipeline disguised as a utility tool when you selectively spare a handful of channels, in a way. Harvesting everyone else's credentials.

When Convenience Costs Your Credentials: The JeeBot Twitch Extension Incident

This incident is a sobering reminder for anyone building or relying on modern software ecosystems. The browser extension marketplace remains a wild west where vetting is often superficial and malicious actors can easily capture thousands of active sessions overnight. While the developer has since patched out the offending behavior, the underlying vulnerability point out how fragile our trust is in third-party code. If you happen to be one of the users who installed JeeBot for better video quality or ad-free viewing, updating the extension isn't enough; you need to immediately revoke your exposed tokens and audit every permission you've granted to your browser.

As software developers and small teams! This we need to push back against, and this matters, the frictionless installation culture that normalizes giving untrusted code full DOM and network access. What's the catch? Anyway, craft demands respect for user privacy. And building secure software means treating login tokens like the high-value secrets they actually are. Convenience is nice, keeping your accounts out of a proxy server's log files is non-negotiable.