CL Suite (marketed as “CL Suite by @CLMasters,” Chrome extension ID: jkphinfhmfkckkcnifhjiplhfoiefffl) is a malicious Google Chrome extension posing as a Meta Business Suite/Facebook Business Manager utility (e.g., scraping Meta Business Suite data, removing verification pop-ups, and generating 2FA codes). Despite privacy-policy claims that 2FA secrets and Business Manager data remain local, the extension exfiltrates sensitive authentication material and business intelligence from meta.com and facebook.com.
High-confidence capabilities and behavior described:
Infection vector / distribution:
Targeting and impact:
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Socket’s Threat Research Team identified a malicious Google Chrome extension CL Suite by @CLMasters (extension ID jkphinfhmfkckkcnifhjiplhfoiefffl), that… exfiltrates TOTP seeds, 2FA codes, Business Manager contact lists, and analytics data to infrastructure controlled by the threat actor.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
"collects Facebook account identifiers, 2FA seeds and codes, CSV exports, tab URL, public IP, and user agent"
"transmits TOTP seeds and current one-time security codes"; "Steal TOTP seed... and 2FA code"
"...transmits TOTP seeds and current one-time security codes ... to a backend at getauth[.]pro, with an option to forward the same payloads to a Telegram channel controlled by the threat actor."; "...transmitted to third-party backend infrastructure controlled by the extension operator"
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious Chrome extension targeting Meta Business Suite/Facebook Business Manager users to exfiltrate TOTP seeds and current 2FA codes, Business Manager contact exports (“People” CSV), and analytics/asset/billing metadata to attacker-controlled infrastructure (and optionally Telegram).
A malicious Google Chrome extension targeting Meta Business Suite/Facebook Business Manager users. It advertises scraping and 2FA-code generation features, but covertly harvests and exfiltrates TOTP seeds and current 2FA codes (neutralizing MFA), plus Business Manager “People” exports and analytics/payment-related data. Exfiltration is sent to getauth[.]pro endpoints using a hardcoded bearer API key and can be mirrored to a threat-actor Telegram channel.
Malicious Chrome extension that steals business-related data (e.g., Meta Business Suite/Facebook Business Manager data), emails, and browsing history; masquerades as a productivity/scraping tool.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.