What Happened
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store - Chrome -
Why It Matters
Report facts: a malicious cross-store Twitch browser extension allegedly leaked OAuth tokens from nearly 31,000 users to proxy servers run by a Russian commercial bot service. The extension was published under the name "Twitch Enhanced Viewer | JeetBot" and appeared in both the Chrome Web Store and Mozilla Firefox Add-ons store. RealGround analysis: this is best classified as an AI supply-chain-adjacent credential leakage event because it involves a compromised third-party extension distributed through trusted app ecosystems, creating downstream account takeover and trust-chain risk for users and organizations that rely on browser extensions.
RealGround Analysis
This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html
