Threat Summary
AlienVault OTX pulse activity identifies a malicious browser-extension campaign branded as Twitch Enhanced Viewer | JeetBot that was distributed through mainstream extension channels, including the Chrome Web Store and Firefox Add-ons. The extension presented itself as a quality-of-life Twitch utility for ad blocking and stream unlocking, while covertly capturing live Twitch OAuth session tokens and forwarding them to infrastructure under jeetbot.cc and related Deno-hosted proxy endpoints. Reported exposure is approximately 30,000 Chrome users and 552 Firefox users, making this a high-utility token theft operation with account-takeover potential rather than a noisy mass malware event.
The attack chain is browser-native and identity-centric: install or update a trojanized extension, inherit broad extension permissions, observe or capture Twitch OAuth/session material during normal browsing, then beacon or POST token material to attacker-controlled endpoints such as /set-token, /extension_helper/, and proxy enumeration routes under /api/v1/proxies and /api/v1/forced-proxy. The objective is likely resale, abuse, or operational use of authenticated Twitch sessions: impersonation, streamer account compromise, chat manipulation, fraud, audience monetization, or pivoting into linked creator-business workflows. Because OAuth tokens can remain valid after password reset if sessions are not revoked, defenders must treat this as credential theft even when no password database was touched.
Threat Actor / Malware Profile
Adversary / service name: JeetBot. The pulse attributes the activity to a Russian-controlled proxy service and identifies the malicious extension as Twitch Enhanced Viewer | JeetBot. No conventional malware family is listed, which is consistent with the tradecraft: the payload is JavaScript delivered through a trusted browser extension model rather than a dropped executable.
Distribution method: Supply-chain-style abuse of official browser extension stores. Social engineering is embedded in the value proposition: ad blocking, stream unlocking, and viewer enhancement for Twitch users. Enterprise risk increases where employees use personal browser profiles on corporate endpoints, sync browser extensions across devices, or access creator, marketing, esports, or social-media operations from managed assets.
Payload behavior: The extension operates inside the browser security context and can read page state, intercept or copy session tokens, alter traffic routing through forced proxy settings, and communicate with remote helper APIs. Expected behaviors include token capture during Twitch authentication or active sessions, transmission of bearer/session material to /set-token, retrieval of proxy lists, and dynamic enforcement of proxy routing via forced-proxy logic.
C2 communication: HTTP URLs in the pulse indicate unencrypted API-style endpoints under api.jeetbot.cc, enhanced.jeetbot.cc, ext-styles.jeetbot.cc, plus Deno-hosted proxy infrastructure at proxy.thebeholder.deno.net and thebeholder-proxy.deno.dev. SOC teams should not assume HTTP is benign merely because content is small; token theft often uses short POST bodies, JSON, or authorization headers.
Persistence mechanism: Persistence is achieved through browser extension installation, update channels, browser profile sync, and potential proxy configuration influence. Removal requires extension uninstall, browser profile cleanup, token revocation, and verification that enterprise policy prevents reinstallation.
Anti-analysis techniques: The campaign blends into legitimate extension workflows, uses benign-looking API paths, separates token ingestion from proxy control across subdomains and Deno apps, and may only activate proxy/token logic for targeted sessions or after remote configuration is fetched. Dynamic analysis should instrument extension background/service-worker traffic and browser net-export logs rather than relying only on endpoint file artifacts.
IOC Analysis
The pulse contains FileHash-SHA256 indicators and URL indicators. Hashes likely represent extension packages, unpacked extension components, or analyzed artifacts; URLs represent token ingestion, helper APIs, and proxy control planes. There are no IPv4/IPv6 indicators in the sample, so DNS resolution and passive DNS become important for infrastructure expansion.
Operationalize the indicators as follows:
- Block and alert on domains/URLs:
api.jeetbot.cc,enhanced.jeetbot.cc,ext-styles.jeetbot.cc,proxy.thebeholder.deno.net, andthebeholder-proxy.deno.dev, including exact paths/set-token,/api/v2/public/extension_helper/,/api/v1/forced-proxy, and/api/v1/proxies. - Add SHA256 hashes
141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fcande17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8to EDR blocklists, browser-extension package analysis queues, and download/proxy detonation workflows. - Hunt for browser processes making connections to these hosts, especially
chrome.exe,firefox.exe,msedge.exe, orbrave.exewith extension service-worker context. - Use tooling such as Chrome
net-export, Firefox about:networking, EDR network telemetry, Zeek/Suricata for HTTP metadata, and Secure Web Gateway logs to decode destination, method, URI, user agent, and payload size.
Detection Engineering
---
title: JeetBot Malicious Browser Extension Token Exfiltration
id: 9f6f4d4c-6b1f-4b7e-9f0d-jeetbot001
description: Detects browser processes communicating with JeetBot token ingestion or proxy-control infrastructure identified in OTX pulse activity.
status: experimental
author: Security Arsenal
logsource:
category: network_connection
product: windows
detection:
selection_image:
Image|endswith:
- '\chrome.exe'
- '\firefox.exe'
- '\msedge.exe'
- '\brave.exe'
selection_domain:
DestinationHostname|contains:
- 'jeetbot.cc'
- 'proxy.thebeholder.deno.net'
- 'thebeholder-proxy.deno.dev'
selection_uri:
DestinationHostname|contains:
- 'api.jeetbot.cc'
- 'enhanced.jeetbot.cc'
- 'ext-styles.jeetbot.cc'
condition: selection_image and (selection_domain or selection_uri)
falsepositives:
- Rare; legitimate corporate browsers should not communicate with these domains.
level: high
tags:
- attack.credential_access
- attack.t1552
- attack.t1071.001
- attack.t1557
fields:
- Image
- ProcessId
- DestinationHostname
- DestinationIp
- DestinationPort
- Initiated
---
title: JeetBot Forced Proxy or Token Endpoint URI
id: 2d6b0f5b-0b6a-4f0e-9d7d-jeetbot002
description: Detects proxy, DNS, or web telemetry containing JeetBot API paths used for token upload, extension helper logic, or proxy retrieval.
status: experimental
author: Security Arsenal
logsource:
category: proxy
detection:
selection_host:
c-host|contains:
- 'jeetbot.cc'
- 'thebeholder.deno.net'
- 'thebeholder-proxy.deno.dev'
selection_path:
cs-uri|contains:
- '/set-token'
- '/api/v2/public/extension_helper/'
- '/api/v1/forced-proxy'
- '/api/v1/proxies'
condition: selection_host or selection_path
falsepositives:
- Threat research sandboxes and security detonation.
level: critical
tags:
- attack.command_and_control
- attack.exfiltration
- attack.t1041
- attack.t1102
date: 2026/10/11
modified: 2026/10/11
let JeetBotHosts = dynamic(['jeetbot.cc','api.jeetbot.cc','enhanced.jeetbot.cc','ext-styles.jeetbot.cc','proxy.thebeholder.deno.net','thebeholder-proxy.deno.dev']);
let JeetBotPaths = dynamic(['/set-token','/api/v2/public/extension_helper/','/api/v1/forced-proxy','/api/v1/proxies']);
DeviceNetworkEvents
| where TimeGenerated >= ago(14d)
| where RemoteUrl has_any (JeetBotHosts) or RemoteUrl has_any (JeetBotPaths)
| extend BrowserProc = iff(InitiatingProcessFileName in~ ('chrome.exe','firefox.exe','msedge.exe','brave.exe'), 'browser', 'other')
| summarize Connections=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), RemoteIps=make_set(RemoteIP), RemoteUrls=make_set(RemoteUrl) by DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, BrowserProc
| order by LastSeen desc;
$ErrorActionPreference = 'SilentlyContinue'
$hosts = @('jeetbot.cc','api.jeetbot.cc','enhanced.jeetbot.cc','ext-styles.jeetbot.cc','proxy.thebeholder.deno.net','thebeholder-proxy.deno.dev')
$hashes = @('141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc','e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8')
Write-Output '[*] DNS cache hits:'
Get-DnsClientCache | Where-Object { $n=$_.Name; $hosts | ForEach-Object { $n -like "*$_*" } } | Select-Object Name, Type, Data, TimeToLive
Write-Output '[*] Active TCP/UDP endpoints resolving to JeetBot infrastructure:'
Get-NetTCPConnection | Where-Object { $_.RemoteAddress } | ForEach-Object { try { $r = Resolve-DnsName $_.RemoteAddress -ErrorAction Stop; if (($r.NameHost + ' ' + $r.Name) -match 'jeetbot|thebeholder') { $_ } } catch {} } | Select-Object LocalAddress, LocalPort, RemoteAddress, RemotePort, State, OwningProcess
Write-Output '[*] Browser extension artifacts containing JeetBot markers:'
$extRoots = @("$env:LOCALAPPDATA\Google\Chrome\User Data","$env:APPDATA\Mozilla\Firefox\Profiles","$env:LOCALAPPDATA\Microsoft\Edge\User Data")
foreach ($root in $extRoots) { if (Test-Path $root) { Get-ChildItem $root -Recurse -Include manifest.json,background.js,content.js -ErrorAction SilentlyContinue | Select-String -Pattern 'jeetbot|set-token|forced-proxy|extension_helper|thebeholder' -List | Select-Object Path, LineNumber, Line } }
Write-Output '[*] Hash sweep in browser extension caches:'
foreach ($root in $extRoots) { if (Test-Path $root) { Get-ChildItem $root -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object { $h=(Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower(); if ($hashes -contains $h) { [PSCustomObject]@{Path=$_.FullName; SHA256=$h} } } } }
Write-Output '[*] Proxy settings inspection:'
Get-ItemProperty 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Internet Settings' | Select-Object ProxyEnable, ProxyServer, AutoConfigURL
Get-ChildItem 'HKLM:\Software\Policies\Google\Chrome\ExtensionInstallForcelist','HKCU:\Software\Policies\Google\Chrome\ExtensionInstallForcelist' -ErrorAction SilentlyContinue
Response Priorities
Immediate: Block JeetBot and Beholder domains/URLs at DNS, secure web gateway, EDR network control, and firewall egress. Force-remove the extension using managed browser policy, disable browser sync for affected users until cleanup is complete, and hunt all endpoints for extension artifacts and browser network connections. Preserve browser profiles, extension directories, net-export logs, and proxy logs before remediation where legal and privacy controls permit.
24h: Treat exposed Twitch OAuth/session material as compromised. Revoke active Twitch sessions and OAuth grants, require reauthentication, review login history and streamer/admin actions, and check for connected-app abuse, payout changes, chat moderation changes, or unusual clips/messages. If corporate identities or social-media operations accounts used the same browser profile, reset sessions there too and review conditional-access sign-in logs for token replay or impossible travel.
1 week: Implement browser-extension allowlisting for managed devices, separate personal and corporate browser profiles, restrict extension permissions for high-risk roles, monitor for forced-proxy behavior, and add detections for browser processes contacting newly registered Deno or token-ingestion endpoints. Update onboarding and creator-team guidance so stream tooling is vetted like software supply chain, not treated as harmless browser customization.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.