Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
Anthropic is reaching out to a number of Claude users after discovering that infostealer malware on their machines has been used to swipe active login sessions, giving attackers a way into accounts and a means to burn through usage allowances. The company is now signing affected users out, stripping saved payment methods, and issuing refunds for unauthorized charges.
Stolen sessions bypass login security
Infostealer malware can copy an already authenticated browser session, meaning the attacker may not need to go through the normal password and 2FA login process again. This is a key detail because it lets a hijacker step into an active session without triggering the usual authentication hurdles.
In an email sent to an affected user, who later shared it on Reddit, Anthropic explained that it had recently become aware of a bad actor using common infostealer malware to steal Claude login sessions from people's computers. The company noted that the attacker then used those sessions to access Claude accounts and consume their usage.
Usage limits draining while idle
For users who noticed strange behavior in their Claude accounts, Anthropic offered a pointed hint: if usage limits looked like they refilled and then drained while the user wasn't actively using Claude, that was likely the cause. This symptom could be a telltale sign that a session has been compromised and is being milked by someone else.
The email further stressed that the malware was not related to Claude itself. Anthropic said it had no reason to believe the malware was installed through Claude or connected to anything the user did with Claude. Instead, the company pointed to general-purpose infostealer malware that typically arrives through downloads or malicious apps.
Malware family list includes Vidar and LummaC2
Anthropic has identified multiple malware families in these attacks, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer (AMOS) on a small number of Macs. This list shows that the attackers are relying on established, widely available infostealer tools rather than a custom-built threat.
The Redditor who shared the email confirmed that they had downloaded a pirated game, which explained how their system got compromised. This fits with the general pattern Anthropic described, where malware often arrives through downloads or malicious apps and collects information stored locally, including browser passwords, login cookies, and credentials belonging to other apps.
Session theft adds to stolen data pile
Anthropic's email described the Claude session as likely one of many things the malware collected. The bad actor appears to have started picking the Claude sessions out of what it collected and using them, according to the company. This suggests a broader harvesting operation where sessions from various services are gathered and later exploited.
We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage.
— Anthropic, in an email sent to an affected user, as shared on Reddit
Refunds and session revocation offered
Anthropic is taking steps to mitigate the damage for affected users. The company will sign users out of Claude, hoping to stop the stolen sessions from being used further. It will also remove saved payment methods to prevent unauthorized purchases and refund charges it identifies as unauthorized.
This response is a direct attempt to cut off the attacker's access and undo any financial harm. However, Anthropic warned that signing users out stops the stolen sessions but does not remove the malware. The company cautioned that if the malware is still on the computer, the next login session could be stolen the same way.
User urged to clean the machine
Anthropic has urged affected users to take basic security steps, including changing credentials, revoking other sessions, and removing the malware from their PCs. These are standard remediation steps, but they are critical given the persistence of the threat.
The company's warning underscores the need to address the root cause: the infected device. Without removing the malware, any new login session could be compromised again, leading to a repeat of the problem.
Why this matters for Claude users
This incident highlights the risks of session-based authentication, especially when a device is compromised. Even strong passwords and 2FA may not protect accounts if an active session is stolen. For users, the takeaway is that securing the device is as important as securing credentials.
As attackers grow more interested in AI services, users should be vigilant about what they download and how they manage their sessions. The fact that Anthropic is offering refunds and actively revoking sessions shows they are taking the issue seriously, but users must also play a part in protecting their own machines.
Sources
- BleepingComputer Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.
TerminalFix Malware Exploits Fake CAPTCHAs
Microsoft warns of TerminalFix ClickFix variant that tricks users into running malicious PowerShell commands via fake Cloudflare checks.