Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions to Drain Usage
Anthropic is warning some Claude users that infostealer malware on their computers is stealing active Claude login sessions, letting attackers access accounts and drain their usage quotas. The company is responding by signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized. Users may notice the attack if their usage limits appear to refill and then drain while they are not actively using Claude.
The stolen sessions allow attackers to bypass normal password and two-factor authentication because infostealers copy already-authenticated browser sessions. Anthropic says the malware is unrelated to Claude itself and typically arrives through downloads or malicious apps, such as pirated software. The company attributes the attacks to several infostealers, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer (AMOS) on a small number of Macs.
When Anthropic detects a compromised account, it revokes the stolen session and removes saved payment methods to prevent unauthorized purchases. The company stresses that the malware likely collected many things from infected machines, with Claude sessions simply being among the data harvested. Users are advised to avoid downloading pirated software and to run malware scans to protect their accounts from similar session-hijacking attacks.