Anthropic warns infostealer malware is hijacking Claude user sessions
Anthropic is warning users that Claude infostealer malware has compromised some accounts by stealing active login sessions directly from infected computers. The company is signing affected users out, removing saved payment methods, and refunding unauthorized charges as part of its response.
In an email shared on Reddit, Anthropic explained the attack vector: “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.” If your usage limits appeared to refill and drain while you weren’t actively using Claude, this was likely the cause.

The threat works because infostealers can copy an already authenticated browser session, bypassing the need for attackers to enter passwords or pass two-factor authentication checks. Claude infostealer malware operates as a general-purpose tool—it collects many things from a compromised system, and attackers have now begun extracting Claude sessions from that haul to gain account access.
How systems got infected and what Anthropic found
Anthropic stressed that the malware is not related to Claude itself, was not installed through Claude, and resulted from nothing users did with the service. One affected user who shared the warning confirmed they had downloaded a pirated game, which explains the initial compromise. The company’s investigation identified multiple strains of Claude infostealer malware on Windows systems, including Vidar, LummaC2, StealC, RedLine, and Acreed, along with Atomic Stealer (AMOS) on a small number of Macs.
As covered earlier, CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks highlighted how attackers exploit valid credentials once they gain initial access—a pattern that mirrors what’s happening here. Similarly, NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions demonstrated how threat actors weaponize stolen session data to compromise user accounts across services.
What users need to do now
Revoking compromised sessions stops the stolen sessions from working, but it does not remove the underlying malware from your computer. If the infection remains, your next login session could be stolen the same way. Anthropic urges affected users to change credentials, revoke other active sessions, and remove the malware from their systems using security tools. Taking these basic security steps is essential to prevent re-compromise after signing back into Claude.
المصدر: BleepingComputer