Anthropic has warned Claude users that infostealer malware on their systems has stolen active Claude login sessions, letting threat actors to log into accounts and using it.
Anthropic is logging out impacted users out of Claude, eliminating saved payment records, and reimbursing unauthorized charges.
When a user shared the incident on Reddit, Anthropic replied in an email that, “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage.”
Anthropic also warned that if “your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause.”
Experts suggest that infostealers can also copy an already verified session, meaning the threat actor doesn’t require the standard password and multi-factor login process again.
Who is responsible?
In the email sent to impacted account users, Anthropic said the investigation is in progress, but the PCs were already compromised standard-purpose infostealer malware.
According to Anthropic, it has “no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude.”
As per the company, the malware usually enters via malicious apps or downloads and steals locally stored data such as login cookies, app credentials, and browser passwords.
"Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them," Anthropic said.
In the reddit incident, the user shared that they downloaded a pirated game, which led to system compromise.
Anthropic has found multiple malware such as StealC, Vidar, LummaC2, Acreed on Windows, RedLine, and Atomic Stealer (AMOS) on Macbooks
If you are impacted, Claude will eliminate hacked sessions and revoke saved payment methods to avoid unapproved purchases.
Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware. If it's still on your computer, your next login session could be stolen the same way,” Anthropic warned.
How to stay safe?
- Impacted users can follow basic security steps such as:
- Changing passwords
- Removing malware from the PCs
- Stopping other sessions
Read the original article: