Threat · curated 30 Aug 2026
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
First reported bleepingcomputer.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Anthropic's warning shows that authenticated AI-service sessions are now a targeted asset for infostealers, letting attackers bypass password and 2FA by replaying stolen browser cookies to hijack Claude accounts and their usage.
Anthropic is warning Claude users that common infostealer malware (Vidar, LummaC2, StealC, RedLine, Acreed on Windows and Atomic Stealer/AMOS on macOS) has stolen active Claude login sessions from infected PCs, letting a bad actor access accounts and drain usage. The company is signing affected users out, removing saved payment methods, and refunding unauthorized charges. Anthropic stresses the malware is not related to Claude and typically arrives via malicious downloads or apps.