Malicious Chrome Extensions Target Meta Business Suite and VKontakte Users
- Securityish
- Privacy & Personal Security
Quick Summary
The Securityish Brief
Researchers have discovered a malicious Chrome extension named CL Suite, associated with the user @CLMasters, which is designed to steal data from Meta Business Suite and Facebook Business Manager. This extension, which has 33 users as of now, was first uploaded to the Chrome Web Store on March 1, 2025. It exfiltrates sensitive information such as TOTP codes, Business Manager contact lists, and analytics data to a backend server controlled by the threat actor.
The extension requests broad access to meta.com and facebook.com, claiming that sensitive data remains local. However, it transmits TOTP seeds and one-time security codes, along with CSV exports of Business Manager ‘People’ data, to a backend at getauth[.]pro. This data collection occurs without users’ knowledge, posing a significant risk to their accounts.
In a related incident, Koi Security reported that around 500,000 VKontakte users have had their accounts hijacked through malicious Chrome extensions masquerading as customization tools. This campaign, known as VK Styles, includes extensions that manipulate user settings and force subscriptions to attacker-controlled groups.
Additionally, a coordinated campaign named AiFrame has emerged, involving 32 browser add-ons that appear to be AI assistants but are actually designed to siphon sensitive data from over 260,000 users. These extensions embed remote interfaces that allow attackers to access sensitive browser capabilities.
Understanding the Risks
The findings underscore the growing trend of malicious browser extensions being used to harvest sensitive data under the guise of legitimate tools. Users should be aware that these extensions can exfiltrate browsing history and other personal information, potentially leading to further attacks.
Given the low number of installations for some malicious extensions, attackers can still identify high-value targets, making it crucial for users to remain vigilant. The combination of data scraping and unauthorized access to accounts poses a serious threat to both individual users and organizations.
To mitigate risks, users should adopt a minimalist approach to browser extensions, only installing those that are necessary and well-reviewed. Regular audits of installed extensions for suspicious behavior or excessive permissions are also recommended.
Key Takeaways
- Only install necessary and well-reviewed Chrome extensions from official sources to reduce the risk of malicious software.
- Regularly audit your installed extensions for any signs of malicious behavior or excessive permission requests.
- Use separate browser profiles for sensitive tasks to limit exposure to potential threats.
- Implement extension allowlisting to block malicious or non-compliant extensions from being installed.
- Monitor your accounts for unusual activity, especially if you use services like Meta Business Suite or VKontakte.
Key Terms & Concepts
- TOTP: In this article, TOTP refers to time-based one-time passwords used for two-factor authentication.
- CSV: CSV stands for Comma-Separated Values, a file format used to store tabular data in plain text.
- VKontakte: VKontakte is a social networking service popular in Russia and other Eastern European countries.
- exfiltrate: Exfiltrate means to transfer data from one system to another, often without authorization.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.