Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

bleepingcomputer+1bleepingcomputer+1searchenginejournal+1Anthropic warned Claude users on Saturday that infostealer malware running on their personal computers had been stealing active login sessions, allowing attackers to access accounts and burn through paid usage. The company responded by forcibly signing out affected users and removing saved payment methods from their accounts.bleepingcomputer+1
"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic said in an email to affected users, first shared by a recipient on Reddit.bleepingcomputer
The campaign exploits session cookies rather than passwords. When a user logs into Claude, the browser stores a session cookie that acts as proof of authentication. Infostealer malware copies that cookie along with other locally stored credentials, allowing attackers to replay the session without ever needing the user's password or two-factor authentication code.pasqualepillitteri
The telltale sign was usage limits that appeared to refill and drain while account holders were not using the service. Anthropic said its own systems flagged the unusual activity.bleepingcomputer+1
The company identified six malware families involved: Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows, along with Atomic Stealer (AMOS) on a small number of Macs. All are well-known, commercially distributed stealers sold in criminal marketplaces — none was written specifically to target Claude.pasqualepillitteri+1
Anthropic stressed that the malware had nothing to do with its platform or servers. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the company wrote. The Reddit user who first shared the notification confirmed they had downloaded a pirated game, which introduced the infostealer to their system.searchenginejournal+1
Phones and tablets do not appear to have been affected. The infections targeted desktop computers running Windows or macOS.secnews+1
Anthropic cautioned that the forced logout neutralizes already-stolen sessions but does not remove the underlying malware. If the infostealer remains on the machine, the next login session can be captured just as easily.pasqualepillitteri+1
The company urged users to run an antivirus scan and clean the device first, then change the password on the email account tied to Claude, and only after that log back in and re-add a payment method. Because infostealers sweep all locally stored credentials, not just those for Claude, Anthropic recommended changing passwords across other services as well, starting with banking and email.pasqualepillitteri
"Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware," Anthropic warned. "If it's still on your computer, your next login session could be stolen the same way."bleepingcomputer