bleepingcomputer.com web signal

Anthropic warns infostealer malware is draining Claude sessions

Anthropic Cybersecurity ai-security

TL;DR

  • Five malware families spanning Windows (Vidar, LummaC2, StealC, RedLine, Acreed) and macOS (Atomic Stealer) are confirmed vectors, showing multi-family targeting of Claude sessions.
  • Attackers replay stolen session cookies rather than cracking passwords, so two-factor authentication provides no protection against this theft method.
  • Anthropic used Claude itself to detect and analyze malware on a compromised device, an early documented case of AI deployed in its own incident response.

Anthropic told Claude users this week that common infostealer malware has been lifting their authenticated session cookies and running up paid usage on hijacked accounts, according to a customer advisory reported by BleepingComputer.

"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic said in the notice quoted by the outlet.

The company named Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer (AMOS) affecting a small number of Mac users. The stealers arrive through malicious downloads or apps and pull locally stored browser passwords, login cookies and credentials. Anthropic was explicit that Claude itself was not the vector: "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude."

For victims, the tell is billing behavior rather than a login prompt. "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause," the notice said. Anthropic said it is revoking the compromised sessions, wiping saved payment methods and refunding unauthorized charges tied to the stolen logins.

None of that closes the hole on the user's own machine. "Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware," the company said, telling affected users to change credentials, revoke active sessions and clean their systems. Paid AI usage now sits on the list of assets commodity stealers monetize, one more entry alongside the 246 AI security stories we have logged in the last 90 days on our cybersecurity page.

What others are reporting

Coverage cluster as of 2h after publish

  1. Search Engine Journal Read →

    Frames the 2FA bypass clearly and reports Anthropic used Claude Opus to analyze malware on a compromised device; security experts quoted suggest remediation may be incomplete.

    We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers