Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

**Infostealer Malware Hijacks Claude Sessions, Draining Usage**

In a disturbing development, users of Anthropic’s popular AI-powered chatbot Claude have reported having their login sessions hijacked by infostealer malware. The attackers are then using these stolen sessions to drain the victims’ usage limits, with some users even reporting unauthorized charges.

According to an email sent out by Anthropic, the company has identified multiple instances of a common type of malware known as infostealers that have been used to steal active Claude login sessions from people’s computers. These infostealers can copy already authenticated browser sessions, allowing attackers to bypass normal password and 2FA login processes.

The affected users are those who have had their computers infected with general-purpose infostealer malware, which typically arrives through downloads or malicious apps and steals information stored locally, including browser passwords, login cookies, and credentials belonging to other apps. In some cases, the victims may not even be aware that they’ve been compromised until they notice suspicious activity on their Claude accounts.

Anthropic has linked these attacks to various types of infostealers, including Vidar, LummaC2, StealC, RedLine, and others. The company’s investigation is ongoing, but it’s clear that the malware was already present on the victims’ computers before the hijacking occurred.

What makes this attack particularly concerning is that once an attacker has valid credentials, they can bypass many security measures and consume the victim’s usage limits without being detected. According to a recent report, only 37% of actions taken by attackers using valid credentials are blocked by security measures.

The good news is that Anthropic is taking steps to mitigate the damage. The company is signing affected users out of Claude, removing saved payment methods to prevent unauthorized purchases, and refunding charges it identifies as unauthorized. However, this does not remove the malware from the victims’ computers, leaving them vulnerable to further attacks.

To protect themselves from similar attacks in the future, users are advised to take basic security steps such as changing their credentials, revoking other sessions, and removing the malware from their PCs. While this attack may be a wake-up call for some users, it’s also an opportunity to remind everyone of the importance of cybersecurity best practices.

As Anthropic continues to investigate this incident, it serves as a reminder that even with robust security measures in place, there is always room for improvement and vigilance.


Source: Bleeping Computer — 2026-08-30