Anthropic Warns Claude Users That Infostealer Malware Is Stealing Login Sessions
Anthropic is warning some Claude users that information-stealing malware, also known as infostealers, may be stealing active Claude login sessions from their computers. Attackers can use these stolen sessions to access accounts and consume users’ Claude usage limits.
In response, Anthropic is signing affected users out of Claude, removing saved payment methods, and refunding charges it determines to be fraudulent.
“We recently became aware of a malicious actor who was using common information-stealing malware to steal Claude login sessions from people’s computers and use those login sessions to access and consume Claude accounts,” Anthropic said in an email sent to affected users. The message was shared on Reddit.
“If your usage limit appears to be refilled while you are not using Claude, and then depleted, this may be the cause,” Anthropic warned.

Source: Reddit
Information-stealing malware can copy authenticated browser sessions, including login cookies. As a result, attackers may be able to access a Claude account without repeating the normal password and two-factor authentication process.
Anthropic Links Claude Account Attacks to Vidar, LummaC2, StealC, RedLine, and Other Infostealers
Anthropic sent the warning to users whose accounts may have been compromised. The company said its investigation is ongoing and that the affected computers may have been infected with generic information-stealing malware.
“There is no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you have done to Claude,” the company stressed.
According to Anthropic, infostealers commonly arrive through malicious downloads, cracked software, or deceptive applications. Once installed, they can steal locally stored data, including browser passwords, login cookies, and credentials for other applications.
“Your Claude session could be one of many things you’ve collected, and now it appears that malicious actors are starting to take Claude sessions from what they’ve collected and use them,” Anthropic said.
Anthropic identified several Windows malware families linked to the activity, including Vidar, LummaC2, StealC, RedLine, and Acreed. The company also observed a small number of Atomic Stealer, also known as AMOS, infections on macOS.
To limit unauthorized access and purchases, Anthropic is revoking compromised Claude sessions and deleting saved payment methods from affected accounts.
“Signing out of Claude will stop the stolen session but will not remove the malware,” Anthropic warned. “If it’s still on your computer, your next login session can be stolen as well.”
Anthropic is urging affected users to take additional security measures, including scanning their devices for malware, changing passwords, and signing out of active sessions on other services. Users should also avoid logging back into Claude from an infected device until the infostealer has been removed.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




