Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data
A malicious Chrome extension named CL Suite by @CLMasters (ID: jkphinfhmfkckkcnifhjiplhfoiefffl) poses a significant threat to Meta Business users by stealing Facebook Business Manager two-factor authentication (2FA) codes and analytics data. This…
A malicious Chrome extension named CL Suite by @CLMasters (ID: jkphinfhmfkckkcnifhjiplhfoiefffl) poses a significant threat to Meta Business users by stealing Facebook Business Manager two-factor authentication (2FA) codes and analytics data. This extension is available in the Chrome Web Store and specifically targets Meta Business Suite and Facebook Business Manager users.
The extension advertises features such as extracting user data, analyzing Business Managers, removing verification popups, and generating 2FA codes. However, it requests extensive permissions over meta.com and facebook.com, which has raised security concerns.
Despite its privacy policy claiming that data remains local, technical reviews by security researchers reveal that the extension operates as an infostealer. It systematically collects authentication secrets and business intelligence from authenticated sessions, particularly targeting two-factor authentication mechanisms for Facebook and Meta Business accounts.
The extension's built-in 2FA generator captures the Time-based One-Time Password (TOTP) seed and the current 6-digit 2FA code. This data is then transmitted to an attacker-controlled server, with the option to forward it to a Telegram channel, allowing attackers to generate valid 2FA codes indefinitely.
This extension is available in the Chrome Web Store and specifically targets Meta Business Suite and Facebook Business Manager users.
The extension also targets Meta Business Manager data by scraping the "People" view, compiling names, email addresses, roles, status, and access levels into CSV files, and exfiltrating these to the attacker's backend. Additionally, it maps business assets by enumerating Business Manager IDs, related ad accounts, connected pages, and payment configurations.
Organizations utilizing Meta Business or Facebook Business Manager should audit browser extensions, remove CL Suite , and treat affected accounts as compromised. Recommended actions include re-enrolling 2FA with new secrets, reviewing Business Manager roles and member access, and monitoring network activity for connections to the attacker's infrastructure.
For long-term security, enterprises should enforce extension allow-lists for administrative browsers and carefully evaluate plugins that offer features like scraping, verification bypass, or in-browser 2FA generation.
Based on reporting by Cyber Security News.
