Anthropic Warns Infostealer Malware is Hijacking Claude Sessions to Drain Usage

Anthropic is alerting Claude users that active login sessions are being hijacked by infostealer malware to drain account usage and resources.

Anthropic has begun notifying affected individuals that malicious actors are exploiting common infostealer malware strains to harvest active Claude login sessions directly from compromised personal computers. The unauthorized access allows threat actors to bypass standard username, password, and multi-factor authentication checks, because the malware copies already authenticated browser sessions.

In response to the campaign, Anthropic is proactively signing out impacted users, stripping saved payment methods from profiles, and issuing refunds for unauthorized charges identified during the security review. According to the company’s notification emails, victims often noticed unexpected fluctuations where their usage limits appeared to rapidly refill and drain while the accounts were inactive.

The investigation has linked the underlying infections to widespread general-purpose infostealers, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows systems, alongside Atomic Stealer (AMOS) targeting a smaller subset of macOS devices. Anthropic emphasized that the malware vector is entirely unrelated to its platform, typically arriving via malicious software downloads, pirated applications, or compromised third-party executables.

“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” Anthropic stated in correspondence sent to affected customers.

Because the intrusion stems from persistent host-level malware rather than an API vulnerability or service breach, the enterprise AI firm warned that simply terminating active sessions is insufficient for long-term remediation. Users whose systems harbor active infections risk having subsequent login sessions harvested repeatedly until the underlying malicious software is thoroughly eradicated from their machines.

“Signing you out of Claude stops the stolen sessions, but it doesn’t remove the malware,” Anthropic warned. “If it’s still on your computer, your next login session could be stolen the same way.”

Security teams advise all impacted organizations and individuals to perform comprehensive endpoint scans, revoke active authentication tokens across other web services, and update compromised credentials immediately following any suspected infostealer infection.

Leave a Reply

Your email address will not be published. Required fields are marked *