Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
extension-plugin-hijackcredential-access-methodmass-credential-exposurethreat-infrastructure-tracking

Malicious Chrome Extensions Used for Social Media Account Hijacking

Updated 3mo agoFirst seen Feb 17, 20262 sources

Security researchers reported multiple malicious Google Chrome extensions being used to hijack social media accounts by abusing the trust and permissions granted to browser add-ons. One campaign targeted Meta Business users with an extension named “CL Suite by @CLMasters” (jkphinfhmfkckkcnifhjiplhfoiefffl) that requested broad access to meta.com and facebook.com and exfiltrated Facebook Business Manager authentication material and analytics. Analysis indicated the extension captured the TOTP seed and current 6-digit 2FA code when users used its built-in “2FA generator,” then sent associated identifiers (e.g., username/email) to attacker infrastructure at getauth[.]pro, with optional forwarding to Telegram—enabling ongoing generation of valid 2FA codes and increasing the likelihood of high-value ad account takeover.

A separate operation hijacked more than 500,000 VKontakte accounts via five Chrome extensions disguised as VK customization tools (e.g., themes). The extensions manipulated accounts without consent (auto-subscribing victims to attacker-controlled groups, resetting settings periodically, and leveraging VK weaknesses to perform unauthorized actions) and could silently update to receive new malicious code. Researchers attributed the VK-focused activity to a single actor (GitHub alias “2vk”), and at least one extension (VK Styles) was removed from the Chrome Web Store after being flagged, underscoring the ongoing risk of extension-based compromise even when distributed through official marketplaces.

Share:
Malicious Chrome Extensions Used for Social Media Account Hijacking
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 17, 20264mo ago

Researchers identify Facebook Business infostealer extension

Socket threat researchers disclosed that the Chrome extension "CL Suite by @CLMasters" was masquerading as a Meta Business utility while stealing Facebook Business Manager 2FA data, analytics, and account configuration details. The extension was reported as still available in the Chrome Web Store and exfiltrating data to attacker-controlled infrastructure including getauth[.]pro.

Feb 16, 20264mo ago

Researchers disclose large-scale VK extension hijacking campaign

Koi Security publicly reported that five related Chrome extensions had been used to hijack more than 500,000 VKontakte accounts, abuse VK security weaknesses, and silently update with new malicious code. The researchers attributed the operation to a single actor using the alias "2vk."

Feb 6, 20265mo ago

Chrome Web Store removes VK Styles extension

At least one malicious extension tied to the VK campaign, VK Styles, was removed from the Chrome Web Store after being flagged. The takedown occurred while the broader operation was being investigated.

Jan 31, 20265mo ago

VK account hijacking campaign continues through January 2026

The malicious VK extension operation remained active through January 2026, primarily affecting Russian-speaking users in Eastern Europe, Central Asia, and the global Russian diaspora. Researchers said the campaign ultimately hijacked more than 500,000 VK accounts and grew attacker-controlled groups to millions of followers.

Jun 15, 20251y ago

Malicious VK-themed Chrome extension campaign begins

A threat actor later linked to the GitHub alias "2vk" began a campaign in mid-2025 using Chrome extensions disguised as VKontakte customization and theme tools. The extensions targeted authenticated VK sessions to manipulate accounts and spread attacker-controlled groups.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Affected products
3 linked
TelegramGithubGoogle Meet
Organizations
6 linked
GoogleSocketMeta PlatformsTelegramKoi SecurityVKontakte
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.