Key Takeaways:
- Infostealer Malware steals active Claude login sessions from users’ infected personal computers.
- Attackers drain account usage limits and abuse saved user payment methods.
- The company is logging out users and refunding all unauthorized charges.
Anthropic recently warned Claude users that infostealer malware on infected computers stole active browser login sessions, allowing attackers to access accounts, drain usage limits, and exploit saved payment methods without needing passwords.
Anthropic Warns of Malware Hijacking Claude Sessions
Anthropic issued an urgent public security warning after discovering a dangerous bad actor using common infostealer malware to target Claude users across the internet.
The malicious software steals active login sessions directly from personal computers, allowing attackers to bypass traditional passwords and security verification codes entirely without triggering any security alerts or warnings.
“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” the company stated in public alerts.
Victims noticed unusual account activity when their usage limits mysteriously refilled and drained while they were away from their personal desks overnight.
Because infostealers copy already authenticated browser sessions, attackers do not need to go through normal password or two-factor authentication login prompts.
The malware typically arrives through malicious downloads or unverified applications, quietly collecting locally stored browser passwords, login cookies, and sensitive application credentials from unsuspecting victims.
Company Takes Action to Protect Affected Accounts
The company is proactively signing affected users out of Claude to stop stolen sessions immediately and prevent further account abuse across platforms. Officials also remove saved payment methods from compromised profiles and issue full cash refunds for any financial charges identified as unauthorized by internal security reviews.
Identified malware strains include Vidar, LummaC2, StealC, RedLine, and Acreed operating on Windows systems. A small number of Mac users faced similar security risks from the Atomic Stealer malware during the active campaign targeting digital enterprise platforms.
Anthropic stressed that its ongoing technical investigation found no indication that the malware is related to Claude itself. The malicious programs are general-purpose stealers that harvest sensitive data from multiple local applications without user awareness or explicit consent.
Experts Urge Users to Secure Systems and Remove Threats
Anthropic emphasized that signing users out does not automatically remove the underlying Infostealer Malware from infected machines. Users must clean their computers thoroughly using security tools to prevent future session thefts from occurring on the compromised personal computer device.
Experts advise victims to change account credentials, revoke other active sessions, and update banking passwords immediately.
People should strictly avoid unofficial downloads and pirated games to keep personal computer systems safe from future cyber threats and malicious digital intrusions.
Security teams continue monitoring the situation closely while assisting affected customers across global regions. Users must maintain high vigilance, secure their primary email accounts, and run complete system scans to ensure absolute device safety moving forward against emerging digital threats and malware attacks.
Visit more of our news! CyberPro Magazine




