Either that or grab a cheap Android handset and use it as a backup. The standard 2FA app on Android needs nothing more than occasional network connectivity to keep the clock in sync. You don't even need a Google account, the app is on FDroid.
Cloudflare is huge and many of us rely on it, so I hope you can easily avoid this predicament in the future - good luck!
I very strongly recommend against doing this: If you do that, you are giving up a lot of security provided by that second factor as the malware you are using 2FA to protect against now also has access to the keys used to create the 2FA token.
If your machine is compromised, it's over.
It can just forward code, relay cookies, etc. 2FA protects against someone peeking at your keyboard, or reused passwords, not malware.
I recently learned that there is an authenticator in f-droid, but not the authenticator, if one reads the notes at the top of the f-droid listing: https://f-droid.org/repository/browse/?fdid=com.google.andro...
I don't even know what they would want to stick in the Play store's authenticator above the already open sourced functionality.
[0] https://github.com/google/google-authenticator-android/wiki [1] https://play.google.com/store/apps/details?id=com.google.and...