# Malicious Chrome Extension CL Suite Steals Meta Business Manager Data & TOTP 2FA Seeds

> Malicious Chrome extension 'CL Suite' by @CLMasters discovered stealing Meta Business Manager data and TOTP 2FA seeds, enabling persistent account takeover of Facebook/Meta business advertising accounts.

- **Published:** 2026-02-13T03:12:00Z
- **Last reviewed:** 2026-02-13T03:12:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0081
- **ID:** TL-2026-0081
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** PATCHED
- **Actor:** CLMasters
- **Detections:** 12 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Socket Security researchers discovered a malicious Chrome extension named 'CL Suite' published by @CLMasters that specifically targets Meta (Facebook) Business Manager users. The extension masquerades as a productivity tool for managing Facebook business operations but covertly exfiltrates sensitive data including Business Manager contact lists, advertising analytics data, and critically, TOTP (Time-based One-Time Password) 2FA seed secrets. By stealing TOTP seeds rather than individual OTP codes, the attacker gains PERSISTENT 2FA bypass capability — they can generate valid authentication codes indefinitely without re-compromising the victim. This is significantly more dangerous than session cookie theft because it survives password resets, session invalidations, and device changes. The extension uses Chrome's content script injection capabilities to interact with Facebook/Meta Business Manager pages, scraping DOM elements containing business data, injecting JavaScript to intercept API responses, and hooking into the 2FA enrollment/management flow to capture TOTP secret keys during setup or viewing. Exfiltrated data is sent to attacker-controlled infrastructure. Meta Business Manager accounts control advertising spend (often $10K-$1M+/month), ad creative management, audience data, and business page administration. Compromised accounts enable: (1) unauthorized ad spend on attacker-controlled campaigns (cryptoscam/malware distribution ads), (2) business intelligence theft (competitor targeting data, customer audiences), (3) brand impersonation through controlled business pages, (4) lateral access to connected Instagram, WhatsApp Business, and Messenger accounts. This attack fits the established pattern of Vietnamese and Chinese threat actors targeting Facebook Business accounts via malicious browser extensions, a category that has generated hundreds of millions of dollars in fraud since 2022.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1176 Software Extensions
- T1539 Steal Web Session Cookie
- T1111 Multi-Factor Authentication Interception
- T1056 Input Capture
- T1555 Credentials from Password Stores
- T1213 Data from Information Repositories
- T1185 Browser Session Hijacking
- T1005 Data from Local System
- T1087 Account Discovery
- T1069 Permission Groups Discovery
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1657 Financial Theft
- T1531 Account Access Removal
- T1585 Establish Accounts
- T1552 Unsecured Credentials
- T1113 Screen Capture
- T1608 Stage Capabilities
- T1528 Steal Application Access Token
- T1526 Cloud Service Discovery
- T1588 Obtain Capabilities

## Sources

- [Malicious Chrome Extension CL Suite Steals Meta Business Manager Exports and TOTP 2FA Seeds](https://socket.dev/blog/malicious-chrome-extension-steals-meta-business-manager-exports-and-totp-2fa-seeds)
- [Chrome Web Store Developer Program Policies](https://developer.chrome.com/docs/webstore/program-policies)
- [Meta Business Help Center — Account Security](https://www.facebook.com/business/help/security)
- [287 Chrome Extensions Exfiltrate Browsing History From 37.4 Million Users](https://cybersecuritynews.com/chrome-extensions-exfiltrate-browsing-history/)
- [TOTP: Time-Based One-Time Password Algorithm (RFC 6238)](https://datatracker.ietf.org/doc/html/rfc6238)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0081
