CL Suite Chrome Extension Steals Meta 2FA
The CL Suite Chrome extension poses a significant threat to Facebook Business Manager users as it secretly siphons off two-factor authentication (2FA) codes and analytics data. This malicious extension, identified as “CL Suite by @CLMasters,” remains accessible on the Chrome Web Store and targets Meta Business Suite environments. Despite claims that data remains local, analysis by Socket’s researchers reveals that the extension functions predominantly as an infostealer. By capturing TOTP seeds and 2FA codes, and transmitting them to an attacker-managed infrastructure, the extension facilitates unauthorized access to user accounts. Additionally, it scrapes sensitive Business Manager contacts and analytics, providing attackers with comprehensive business insights. Businesses utilizing Meta’s tools are advised to audit and remove the extension, enact new 2FA protocols, and monitor potential data breaches. Implementing strict browser extension lists is essential to safeguarding against such threats. For the complete story and implications, please visit the official news article at cyber security news.
Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data
