2 days ago
Anthropic Warns Claude Users of Malware-Stealing Login Sessions
Anthropic warned some Claude users that harmful software may be on their computers.
This software is called an infostealer because it secretly copies information such as passwords and browser login details.
It may also copy temporary Claude login sessions.
Attackers can use those sessions without knowing the user’s password.
A warning sign is when Claude limits refill and then disappear even though the person is not using Claude.
Anthropic said the malware probably did not come from Claude.
It appears to have affected Windows computers and a small number of Mac computers, rather than phones or tablets.
Users should scan their computers, change important passwords, and turn on two-factor authentication.
Anthropic is logging affected users out and addressing unauthorized charges.
Anthropic warned some Claude users that infostealer malware may have stolen their login sessions from infected computers.
Attackers could use stolen sessions to access Claude accounts without passwords and consume users’ account limits.
Unusual activity may include Claude limits refilling and then being depleted while the account is not in use.
Anthropic said the malware appears unrelated to Claude and likely arrived through unofficial downloads or malicious applications.
The company is signing out affected users, revoking stolen sessions, removing saved payment methods, and refunding identified unauthorized charges.
- Who
- Anthropic, affected Claude users, and attackers allegedly using infostealer malware.
- What
- Infostealer malware allegedly stole Claude login sessions, allowing attackers to access accounts and use their account limits.
- Where
- The suspected malware affected computers, primarily Windows PCs and a small number of Mac computers; phones and tablets did not appear to be involved.
- When
- Anthropic said it had recently become aware of the activity; the articles do not give an exact date.
- Why
- Attackers allegedly harvested browser data and authenticated Claude sessions from infected computers, then used those sessions to access accounts.
Anthropic’s Assessment
Security Implications
Source of the malware
Anthropic’s Assessment
Anthropic said it had no reason to believe the malware came through Claude, was installed by Claude, or was connected to users’ Claude activity.
Security Implications
The incident nevertheless shows that Claude sessions can become one of the items harvested by general-purpose infostealer malware.
Scope of affected devices
Anthropic’s Assessment
Anthropic said its investigation indicated that computers were affected and that phones and tablets did not appear to be involved.
Security Implications
Reports identified infections on Windows computers and a small number of Mac computers, while the total number of affected users was not specified.
Limits of logging out
Anthropic’s Assessment
Anthropic is logging affected users out, revoking stolen sessions, and removing saved payment methods to protect compromised accounts.
Security Implications
Logging out alone does not remove malware; Anthropic warned that a new login could also be stolen unless the computer is scanned and other accounts are secured.
Key facts
- Company
- Anthropic
- Product
- Claude
- Threat
- Infostealer malware that can copy passwords, browser cookies, login sessions, and stored credentials
- Potential impact
- Attackers could bypass passwords and two-factor authentication, access Claude accounts, and deplete usage limits
- Warning sign
- Claude usage limits replenishing and then being depleted while the user was not using the service
- Malware identified
- Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) in a small number of Mac cases
- Recommended response
- Scan the computer, secure the linked email account, revoke active sessions, update other passwords, enable two-factor authentication, and review payment activity
Quotes
Anthropic
AI company that operates the Claude service
“If you noticed your usage limits replenishing and then depleting while you weren't using Claude, this was likely the cause.”
thehansindia.com
“If it remains on your computer, your next login session could be stolen in the same way.”
thehansindia.com








