What Happened
Anthropic has warned a subset of Claude users that widely circulating infostealer malware has been harvesting their active Claude login sessions directly from infected computers, and that attackers have now begun using those stolen sessions to log in as the victim and drain their account usage. The company identified several common infostealer families behind the activity — Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer (AMOS) on macOS. Anthropic said: "It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them."
Incident Details
| Attribute | Value |
|---|---|
| Vector | Commodity infostealer malware on victims' own devices |
| Malware Families | Vidar, LummaC2, StealC, RedLine, Acreed (Windows); Atomic Stealer / AMOS (macOS) |
| What Was Stolen | Active Claude login sessions, browser passwords/cookies, credentials for other apps, stored payment methods |
| Distribution Method | Pirated software downloads and malicious applications |
| Anthropic's Response | Revoked compromised sessions, removed saved payment methods, issued refunds, notified affected users |
How It Works
Infostealers Don't Attack Claude — They Attack the Device
Infostealer malware is designed to sweep an infected machine for anything of value: saved browser passwords, cryptocurrency wallet files, and — critically — authenticated session tokens and cookies sitting in the browser. Because a signed-in Claude session already carries a valid authentication token, an attacker who steals that token can act as the logged-in user without needing the password or a second factor — normal login protections never come into play.
From Bulk Collection to Targeted Abuse
Infostealer logs are typically harvested in bulk and traded or dumped by criminal groups with little immediate discrimination about what's inside. Anthropic's disclosure indicates that a threat actor has since gone back through previously collected logs specifically to extract and reuse the Claude session tokens, turning passive data theft into active account abuse — including running up usage on the AI service and, in some cases, charging saved payment methods.
How Victims Noticed
Anthropic pointed to a specific symptom affected users should watch for: "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause." One affected user confirmed their infection traced back to a pirated video game download, consistent with infostealers' most common distribution channel.
Not a Claude Vulnerability
Anthropic was explicit that this is not a flaw in Claude itself: "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude." The compromise originates entirely from malware already present on the user's device, capturing whatever authenticated sessions happen to be active in the browser — Claude included.
Impact Assessment
| Impact Area | Description |
|---|---|
| Account Abuse | Attackers consumed victims' Claude usage allowances using hijacked sessions |
| Financial Exposure | Stored payment methods on affected accounts were at risk of unauthorized charges |
| Broader Compromise | Infostealers that captured Claude sessions typically also captured passwords and cookies for other services on the same device |
| Detection Difficulty | Session-token theft bypasses password and two-factor authentication checks entirely, leaving no failed-login trail |
Recommendations
For Affected or Potentially Affected Users
- If usage appears to drain without corresponding activity, treat it as a probable sign of session hijacking and act immediately.
- Run a full malware/antivirus scan and remove any identified infostealer before doing anything else — resetting credentials on an infected machine will just have them stolen again.
- Change your Claude password and any reused passwords on other services from a clean device.
- Revoke active sessions on Claude and any other accounts that may have been accessed from the infected device.
- Review payment methods on file for unauthorized charges and remove saved cards if in doubt.
For Organizations
- Reinforce policies against installing pirated software or unverified applications on any device used to access corporate or paid SaaS accounts, including AI tools.
- Consider session-anomaly monitoring (impossible-travel logins, unusual usage spikes) for accounts tied to paid AI services, which are increasingly valuable targets for credential and session theft.
Key Takeaways
- Commodity infostealers — Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer — are stealing active Claude browser sessions from infected devices.
- Stolen session tokens let attackers act as the logged-in user, bypassing passwords and two-factor authentication entirely.
- A threat actor has begun actively reusing previously harvested Claude sessions to drain usage limits and, in some cases, attempt unauthorized charges.
- The most common infection vector reported was pirated software downloads, not any weakness in Claude itself.
- Anthropic has revoked affected sessions, removed saved payment methods, and issued refunds to impacted users.
- Users should watch for usage that refills and drains unexpectedly, scan for malware, and rotate credentials from a clean device if affected.