Infostealers Hijack Claude Sessions to Drain AI Usage
The activity does not indicate a breach of Anthropic or malware delivered by Claude. Anthropic told affected customers that the infections were on computers used to access the service. The number of affected users has not been disclosed, and the company has not publicly identified the actor behind the campaign.
SecurityWeek reported that notifications linked Windows infections to Vidar, Lumma, StealC, RedLine and Acreed, while a small number of macOS devices were associated with Atomic Stealer, also known as AMOS. These general-purpose information stealers commonly collect browser cookies, saved passwords and credentials stored by local applications. No new vulnerability or CVE has been associated with the Claude account activity.
The access method relies on capturing an authenticated browser session rather than defeating a password or multi-factor authentication challenge. A valid session token can let an attacker resume an existing login until the service revokes it or it expires. BleepingComputer reported that unexplained usage depletion, including limits appearing to refill and then drain while the customer was idle, was one sign cited in Anthropic notifications.
Anthropic advised recipients to remove the malware before returning to the service because signing out alone does not clean an infected endpoint and a new session could be stolen again. Dark Reading reported that the company also recommended securing the email account connected to Claude by changing its password, signing out other devices and enabling two-factor authentication after the endpoint is clean. Users should review other credentials and browser sessions exposed on the same device because infostealers collect more than Claude data.
Defenders investigating affected systems should isolate the device, preserve evidence, scan for information-stealing malware and revoke active sessions from a trusted computer. Account activity, payment records and usage histories should be reviewed for unauthorized access. The campaign shows why session revocation and endpoint remediation must accompany password resets when browser authentication data has been stolen.