{"id":10708,"date":"2026-02-17T10:04:57","date_gmt":"2026-02-17T10:04:57","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/17\/malicious-chrome-extension-steals-facebook-business-manage-2fa-codes-and-analytics-data\/"},"modified":"2026-02-17T10:04:57","modified_gmt":"2026-02-17T10:04:57","slug":"malicious-chrome-extension-steals-facebook-business-manage-2fa-codes-and-analytics-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/17\/malicious-chrome-extension-steals-facebook-business-manage-2fa-codes-and-analytics-data\/","title":{"rendered":"Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data"},"content":{"rendered":"<p>    Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A malicious Chrome extension <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">that claims to help Meta Business users quietly\u00a0<a href=\"https:\/\/cybersecuritynews.com\/hackers-hijack-facebook\/\" target=\"_blank\" rel=\"noopener\">steals<\/a><\/span><a href=\"https:\/\/cybersecuritynews.com\/hackers-hijack-facebook\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Facebook Business Manager <\/a>2FA codes and analytics data, putting high\u2011value ad accounts at risk of takeover.<\/p>\n<p>The extension, \u201cCL Suite by @CLMasters\u201d (ID: jkphinfhmfkckkcnifhjiplhfoiefffl), is still available in the Chrome Web Store and specifically targets Meta Business Suite and Facebook Business Manager environments.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhOrtCpsvUDjv5oUwQQ4eQw0P92AiCMexIOoFbTs4C8ya9Rd0l0JD5eClO1oZ8BB6l4xYbGCPxuCdiA5QIXfr8xnIUZTF0EJNDu2_nrBwgJiTCCXeEpete3Qj7RqXWobVcdnQ3hMma72mc5YrhJHOhGxKxQCxuAT9G0bEJsfqJ_ph60GONitMsR-BAE2_s\/s1600\/Screenshot%25202026-02-17%2520123655%2520%25281%2529.webp?ssl=1\" alt=\"Socket AI Scanner\u2019s analysis of the malicious CL Suite by @CLMasters Chrome extension( source : socket)\"><figcaption class=\"wp-element-caption\">Socket AI Scanner\u2019s analysis of the malicious CL Suite by @CLMasters Chrome extension (source: socket)<\/figcaption><\/figure>\n<p>Marketed as a utility to \u201cextract people data, analyze Business Managers, remove verification popups, and generate 2FA codes,\u201d CL Suite requests broad permissions over meta.com and facebook.com.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-from-productivity-tool-to-infostealer\"><strong>From Productivity Tool to Infostealer<\/strong><\/h2>\n<p>Its privacy policy claims that 2FA secrets and Business Manager data remain local in the browser. However, technical analysis shows the extension <a href=\"https:\/\/cybersecuritynews.com\/new-loader-malware-dubbed-quirkyloader\/\" target=\"_blank\" rel=\"noreferrer noopener\">behaves more like an\u00a0infostealer<\/a> than a productivity tool.<\/p>\n<p>Socket\u2019s Threat Researchers found that it systematically abuses the very features it advertises to harvest authentication secrets and business intelligence from authenticated admin sessions.<\/p>\n<p>The most serious issue is how the extension handles<a href=\"https:\/\/cybersecuritynews.com\/fortigate-firewall-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\"> two\u2011factor authentication<\/a> for Facebook and Meta Business accounts.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEid6T_V58B65Ei4OEhL0mjxGSqgl7NlDV7i6f1OKXpqLduXpM05I4CM8hgprVnOtc_UHWtUBzKjxTfvQTE9GnpRbEBtdqiqv_cmJmEPH8HhH8rqhI3TFATu0QeXgxzLyCd6RkHqien9_D_-ZvmWt1te7yHXWx2M8n5vJhAN8madgYl330i2gdWPAQhIaxA\/s1600\/Screenshot%25202026-02-17%2520123739%2520%25281%2529.webp?ssl=1\" alt=\"Chrome Web Store listing for the\u00a0CL Suite by @CLMasters\u00a0extension ( source : socket)\"><figcaption class=\"wp-element-caption\">Chrome Web Store listing for the\u00a0<code>CL Suite by @CLMasters<\/code>\u00a0extension ( source : socket)<\/figcaption><\/figure>\n<p>When users rely on its built\u2011in 2FA generator, <a href=\"https:\/\/cybersecuritynews.com\/github-enhances-npms-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">CL Suite captures the TOTP seed<\/a>, the current 6\u2011digit 2FA code.<\/p>\n<p>The associated Facebook username and email are then sent to an attacker\u2011controlled infrastructure at getauth[.]pro, with an option to forward it to a Telegram channel.<\/p>\n<p>With both the seed and a timestamped, valid code, attackers can continue to generate working 2FA codes indefinitely, making it easy to <a href=\"https:\/\/cybersecuritynews.com\/oauth-framework-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener\">hijack accounts once passwords<\/a> or recovery channels are obtained from infostealers or credential dumps.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-business-manager-contacts-and-analytics-harvested\"><strong>Business Manager Contacts and Analytics Harvested<\/strong><\/h2>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhusj_OcfA650XwcN8vqMUGDoMn-K7D9W_GlFU6hQ6cSZyYunBhY3grwavVFEUkPc9PoD8adRMFzN8XUm-bx-GbzX3PSKX94Yi80WxnLQkqu_U-a9XjdOnHmknQ2iRZ44O9YJk3GrFpzF2J6nkh_FrucN6j5z9CHitMIj3Nj8DefHRUnOW6UBv2mpMNfmQ\/s1025\/Screenshot%25202026-02-17%2520123859%2520%25281%2529.webp?ssl=1\" alt=\"Meta\u2019s official business tools page (source : socket)\"><figcaption class=\"wp-element-caption\">Meta\u2019s official business tools page (source: socket)<\/figcaption><\/figure>\n<p>The extension also aggressively targets Meta Business Manager data.<\/p>\n<p>A \u201cPeople\u201d extraction feature scrapes the Business Manager \u201cPeople\u201d view, builds CSV files with names, email addresses, roles, status, and access levels, and silently exfiltrates those CSVs to the same backend, often marked for Telegram forwarding.<\/p>\n<p>Another analytics component enumerates Business Manager IDs, linked ad accounts, connected pages, and billing or payment configurations, giving attackers a complete map of business assets and how ad spend is funded.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiNi6Bl6YXKCyby3uPocrecMbozeBikkp72Rqbzwa1eghk7G8w55lrJqFU7Bx5_RYiKrbA-doiJ_evrB2NXQ679opLXJYIbYIo7vX2EWA7DFbiCw8WmBnYFx08-zrGA960qtIavloDAC0ePloPxVbG_zrHAYCm29-FHANclVNE9wnhgvFFOzSNY-32RDXg\/s1600\/Screenshot%25202026-02-17%2520123927%2520%25281%2529.webp?ssl=1\" alt=\"Privacy policy page for Meta Business Suite Tools on\u00a0clmasters[.]pro(source : socket)\"><figcaption class=\"wp-element-caption\"><em>Privacy policy page for Meta Business Suite Tools on\u00a0<code>clmasters[.]pro<\/code><\/em>(source: socket)<\/figcaption><\/figure>\n<p>Even with a limited install base, this visibility is enough to identify successful targets and plan follow\u2011on fraud or account\u2011takeover activity.<\/p>\n<p><a href=\"https:\/\/socket.dev\/blog\/malicious-chrome-extension-steals-meta-business-manager-exports-and-totp-2fa-seeds\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to Socket\u2019s Threat Research,<\/a> organizations using Meta Business or Facebook Business Manager should audit browser extensions, remove CL Suite, and treat affected accounts as compromised.<\/p>\n<p>Recommended steps include re\u2011enrolling 2FA with fresh secrets, reviewing Business Manager roles and members, and monitoring for traffic to getauth[.]pro and related infrastructure.<\/p>\n<p>Long-term, enterprises should enforce extension allow\u2011lists for admin browsers and closely scrutinize any plugin that offers scraping, verification bypass, or in\u2011browser 2FA generation for high\u2011value platforms.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chrome-extension-steals-facebook-2fa-codes\/\">Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chrome-extension-steals-facebook-2fa-codes\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data A malicious Chrome extension that claims to help Meta Business users quietly\u00a0steals Facebook Business Manager 2FA codes and analytics data, putting high\u2011value ad accounts at risk of takeover. The extension, \u201cCL Suite by @CLMasters\u201d (ID: jkphinfhmfkckkcnifhjiplhfoiefffl), is still available in the Chrome Web [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[768,1636,129,63],"tags":[130],"class_list":["post-10708","post","type-post","status-publish","format-standard","hentry","category-chrome","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10708"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10708"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10708\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10708"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}