TL;DR

['CL Suite chrome extension compromised user data associated with Meta Business Suite and Facebook Business Manager']

What happened

['A Google Chrome extension named CL Suite by @CLMasters (ID: jkphinfhmfkckkcnifhjiplhfoiefffl) was found to be stealing sensitive business data, emails, and browsing history from users of Meta Business Suite and Facebook Business Manager']

Why it matters for ops

['The compromised extension can exfiltrate critical data, posing significant risks to business operations and security.']

Mitigation

  • Remove the malicious Chrome extension immediately
  • Enable strict privacy settings and review permissions granted to other extensions

Action items

  • Audit installed Chrome extensions for suspicious activities
  • Update security policies to restrict potentially risky extensions

Detection IOCs

  • Extension ID: jkphinfhmfkckkcnifhjiplhfoiefffl
  • Abnormal data exfiltration patterns
  • Unusual network requests to unknown endpoints

Source link

https://thehackernews.com/2026/02/malicious-chrome-extensions-caught.html