Anthropic alerts Claude users after infostealer hijacks sessions
Anthropic told some Claude users that infostealer malware on their computers allowed attackers to hijack login sessions and run up usage limits using stolen session data.
Anthropic notified affected customers by email that infostealer malware on their devices enabled attackers to hijack active Claude login sessions and consume usage limits without the account owner’s participation.
The company identified several Windows infostealer families involved in the campaign, including Vidar, Lumma, StealC, RedLine and Acreed. A small number of macOS devices were infected with Atomic Stealer (AMOS). Anthropic described the malware as general-purpose and unrelated to the Claude service, and said it typically arrives through unofficial downloads or malicious applications.
The malware quietly copies saved passwords, browser login cookies and credentials for other local applications. Anthropic reported that a threat actor reviewed the harvested data, selected valid Claude sessions and reused those sessions to access accounts. Users who saw usage limits refill and then drain without actively using Claude were likely affected by that session reuse.
To contain the activity, Anthropic signed out compromised sessions it identified and warned it may sign users out again if it detects further signs of account misuse. The company removed stored payment methods from affected accounts to prevent unauthorized charges and refunded any Claude charges it determined were not authorized.
Customers were instructed to remove the malware from their devices before restoring session access or adding payment information. Anthropic has not attributed the campaign to a specific threat group.
Infostealer families such as Vidar and RedLine are known for collecting browser-stored credentials and cookies, which can let attackers access online accounts when session tokens and saved logins are exposed on infected machines.








