Threat · curated 4 Sep 2026
Anthropic Warns Claude Users of Infostealer Malware Infections
First reported securityweek.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Anthropic's disclosure shows that stolen browser sessions are being weaponized to take over accounts on a major AI platform, turning generic infostealer infections into direct abuse of paid LLM services.
Anthropic warned Claude users that general-purpose infostealer malware (Vidar, Lumma, StealC, RedLine, Acreed on Windows and Atomic Stealer/AMOS on macOS) harvested browser cookies and credentials, allowing a threat actor to hijack their Claude login sessions and drain usage limits. Anthropic signed out compromised sessions, removed saved payment methods, and refunded unauthorized charges.