Threat · curated 30 Aug 2026

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Coverage timeline

30 Aug 2026bleepingcomputer.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Anthropic's warning shows that authenticated AI-service sessions are now a targeted asset for infostealers, letting attackers bypass password and 2FA by replaying stolen browser cookies to hijack Claude accounts and their usage.

Anthropic is warning Claude users that common infostealer malware (Vidar, LummaC2, StealC, RedLine, Acreed on Windows and Atomic Stealer/AMOS on macOS) has stolen active Claude login sessions from infected PCs, letting a bad actor access accounts and drain usage. The company is signing affected users out, removing saved payment methods, and refunding unauthorized charges. Anthropic stresses the malware is not related to Claude and typically arrives via malicious downloads or apps.