Anthropic Warns Users of Infostealer Malware Hijacking Claude Sessions
Anthropic has warned some users that their computers may be infected with infostealer malware, which allowed attackers to hijack active Claude login sessions and consume usage credits without needing passwords. The company has been signing affected users out of their accounts and removing saved payment methods to prevent further unauthorized charges. The security issue came to public attention after a user shared an email from Anthropic on Reddit. The notification stated that Anthropic had detected suspicious activity and identified multiple infostealer malware families affecting Windows and macOS computers. According to the company, the malware steals authenticated browser sessions, allowing attackers to bypass passwords, multi-factor authentication, and single sign-on protections to access paid Claude accounts. Anthropic emphasized that the malware is not connected to Claude itself. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the company stated in its notification.