Threat · curated 4 Sep 2026

Anthropic Warns Claude Users of Infostealer Malware Infections

Coverage timeline

31 Aug 2026securityweek.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Anthropic's disclosure shows that stolen browser sessions are being weaponized to take over accounts on a major AI platform, turning generic infostealer infections into direct abuse of paid LLM services.

Anthropic warned Claude users that general-purpose infostealer malware (Vidar, Lumma, StealC, RedLine, Acreed on Windows and Atomic Stealer/AMOS on macOS) harvested browser cookies and credentials, allowing a threat actor to hijack their Claude login sessions and drain usage limits. Anthropic signed out compromised sessions, removed saved payment methods, and refunded unauthorized charges.