Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
extension-plugin-hijackcredential-access-methoddata-exfiltration-methodidentity-authentication-vulnerability

Malicious Chrome Extension Exfiltrates Meta Business Data and TOTP 2FA Seeds

Updated 3mo agoFirst seen Feb 13, 20262 sources

Researchers reported a malicious Google Chrome extension, CL Suite (publisher @CLMasters, extension ID jkphinfhmfkckkcnifhjiplhfoiefffl), that targets users of Meta Business Suite and Facebook Business Manager by masquerading as a tool to scrape business data, remove verification pop-ups, and generate 2FA codes. Although its listing and privacy policy claim sensitive data remains local, analysis found the extension requests broad access to meta.com and facebook.com and covertly collects TOTP seeds, current 2FA codes, Business Manager “People” exports (CSV), contact lists, and analytics data.

The stolen data is exfiltrated to attacker-controlled infrastructure at getauth[.]pro, with an option to forward the same payloads to an attacker-controlled Telegram channel. By capturing TOTP seeds and one-time codes, the extension can effectively neutralize 2FA, enabling account takeover when paired with passwords obtained elsewhere (e.g., infostealer logs or credential dumps). The exposure can persist even after uninstall because the attacker retains the exported business intelligence and 2FA seeds; Socket stated it notified Google and flagged the extension for removal, while reporting indicated the extension had a limited user base at the time of analysis.

Share:
Malicious Chrome Extension Exfiltrates Meta Business Data and TOTP 2FA Seeds
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Feb 13, 20265mo ago

Socket reports extension still live in Chrome Web Store and notifies Google

At the time of Socket's publication, the malicious extension was still available in the Chrome Web Store. Socket said it had notified Google and flagged the extension for removal.

Researchers identify malicious 'CL Suite by @CLMasters' Chrome extension

Security researchers found that the Chrome extension 'CL Suite by @CLMasters,' marketed as a Meta Business Suite/Facebook Business Manager tool, covertly steals sensitive Meta business data. The extension was observed exfiltrating TOTP seeds, current 2FA codes, Business Manager exports, analytics, and victim fingerprinting data to attacker-controlled infrastructure.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

22 LINKEDOpen in app
Threat actors
2 linked
Affected products
5 linked
TelegramGithubGmailFacebookInstagram
Organizations
12 linked
SocketMeta PlatformsGoogleMozillaAmazon Web ServicesKoi SecurityLayerXGitHubSimilarwebVKontakteQ ContinuumTelegram
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.