Find notable cyber news and cases, enriched with sources, timelines, and signals.

CL Suite Chrome extension stealing Meta Business data

Malware Activity
First reported
Last updated
Happening score
H score 21
1 unique sources, 1 articles

Summary

Hide ▲

The CL Suite Chrome extension is exfiltrating TOTP seeds, current 2FA codes, and Meta Business data from Meta Business Suite and Facebook Business Manager users, creating a path to follow-on account access. It was first uploaded to the Chrome Web Store on March 1, 2025 and had 33 users as of writing. The extension requests broad access to meta.com and facebook.com and sends stolen payloads to getauth[.]pro. It can also forward the same data to a Telegram channel controlled by the operator.

Related Happenings

Chrome Web Store malicious extensions coordinated campaign using shared C2

Campaign
First: 14.04.2026 23:33 Last: 14.04.2026 23:33 Sources 1

About this happening: A coordinated **Chrome Web Store** extension operation is stealing **Google OAuth2 Bearer tokens**, deploying **backdoors**, and running **ad fraud** across more than **100 malici...

108 Malicious Google Chrome extensions sharing a C2 backend

Malware Activity
First: 14.04.2026 11:35 Last: 14.04.2026 11:35 Sources 1

About this happening: **108 malicious Google Chrome extensions** were found to use the same **C2 infrastructure** to steal credentials, sessions, and browsing data while injecting ads and arbitrary Jav...

Perplexity Comet prompt-injection research shows agentic browsers can be trained into phishing traps

Technical Analysis
First: 11.03.2026 18:38 Last: 11.03.2026 18:38 Sources 1

About this happening: **Perplexity's Comet AI browser** is the focus of a **technical analysis** thread showing how **prompt injection** and **malicious URLs** can steer an agentic browser into **data...

Fake Google Account security page PWA phishing campaign

Campaign
First: 02.03.2026 22:23 Last: 02.03.2026 22:23 Sources 1

About this happening: A **phishing campaign** is using a **fake Google Account security page** and a **Progressive Web App (PWA)** to steal **one-time passcodes**, harvest **cryptocurrency wallet addre...

QuickLens - Search Screen with Google Lens hit by network compromise

Incident
First: 28.02.2026 21:18 Last: 28.02.2026 21:18 Sources 1

About this happening: The **QuickLens - Search Screen with Google Lens** Chrome extension was **compromised** and used to **push malware** to about **7,000 users**, creating risk of **credential theft*...

Timeline

  1. 13.02.2026 13:25 1 articles · 3mo ago

    CL Suite first uploaded to Chrome Web Store

    Untyped Phase

    CL Suite by @CLMasters is first uploaded to the Chrome Web Store as a Google Chrome extension with ID jkphinfhmfkckkcnifhjiplhfoiefffl, establishing the add-on's distribution point before its later use against Meta Business Suite and Facebook Business Manager users.

    Show sources
  2. 13.02.2026 13:25 2 articles · 3mo ago

    CL Suite disclosed stealing Meta Business data

    Initial Disclosure

    Researchers disclose that CL Suite by @CLMasters targets Meta Business Suite and Facebook Business Manager users, requests broad access to meta.com and facebook.com, and exfiltrates TOTP seeds, current one-time security codes, Meta Business 'People' CSV exports, and Business Manager analytics data to getauth[.]pro, with optional forwarding to a Telegram channel controlled by the operator; Socket also warns that the low install count still gives the threat actor enough information to identify high-value targets and mount follow-on attacks.

    Show sources