Skip to main content
Emerging ThreatsMalware & Ransomware

Anthropic Warns of Infostealer Malware Hijacking Claude Sessions

Person sitting at desk with laptop, looking worried, surrounded by papers and notes in a calm home office setting.

"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic told an affected user in an email shared on Reddit.

Anthropic's response: sign-outs, payment removals, and refunds

Anthropic says it is actively signing affected users out of Claude, removing saved payment methods from compromised accounts, and refunding charges it identifies as unauthorized. The company told affected customers that signing them out "stops the stolen sessions," but warned this does not remove the malware from infected machines and therefore does not guarantee subsequent login attempts will be safe while the infection remains.

How infostealer malware is being used to drain Claude usage

Anthropic's investigation, which the company describes as ongoing, links the incidents to general-purpose infostealer malware already present on users' devices. The attackers are not breaking Claude's authentication; instead they are copying active, authenticated browser sessions. As Anthropic explained, "infostealers can copy an already authenticated browser session, which means the attacker may not need to go through the normal password and 2FA login process again."

Anthropic also warned users that an observed symptom of compromise is usage limits that "looked like they refilled and then drained while you weren't using Claude." In those cases, the company said, the stolen session was likely the cause.

Malware families Anthropic identified

  • On Windows, Anthropic named Vidar, LummaC2, StealC, RedLine and Acreed as infostealers it has identified in these incidents.
  • On macOS, Anthropic reported a small number of infections involving Atomic Stealer (AMOS).

The company emphasized that it has "no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude." Instead, Anthropic says the malware typically arrives via downloads or malicious apps and collects locally stored data such as browser passwords, login cookies, and credentials for other apps — with Claude sessions being one of many items harvested.

Remediation steps Anthropic urges affected users to take

Anthropic asked compromised users to take basic, specific steps: change credentials, revoke other active sessions, and remove the malware from their PCs. The company reiterated that revoking sessions will halt current stolen sessions but will not sanitize the device itself — meaning attackers could re-capture a session on the next login if the device remains infected.

What this means for technologists, affected users, and enterprises

  • Technologists and security teams: Anthropic's note and the identification of multiple infostealer families underline that session theft via locally stored browser data is an active tactic; teams will need to account for post-compromise session abuse when evaluating prevention metrics.
  • Affected users and the general public: Anthropic pointed to routine sources of infection — for example, a Reddit user who confirmed their system was compromised after downloading a pirated game — and advised the practical steps above (change credentials, revoke sessions, remove malware).
  • Enterprises and procurement leaders: The company’s action to remove payment methods and refund unauthorized charges highlights one mitigation path for consumer-facing services, but Anthropic's warning that device infections remain a root cause indicates endpoint hygiene and malware removal remain critical.

Anthropic also noted a broader point about defensive measures: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." The company is continuing its investigation while taking the concrete steps it can to stop stolen sessions and limit financial harm to customers.

Original story