
According to a report by bleepingcomputer yesterday, Anthropic warned some Claude users that information-stealing malware on their computers had stolen active Claude login sessions, allowing attackers to access their accounts and steal usage data.

Anthropic is also signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized.
According to an email shared by a Reddit user, Anthropic told affected users: “We recently discovered that malicious actors used common information-stealing malware to steal Claude login sessions from users’ computers, then used those sessions to access Claude accounts and steal their usage.”
Notably, information stealers can copy authenticated browser sessions, meaning attackers may not need to go through the normal password and two-factor authentication login process.
In the email, Anthropic said its investigation is still ongoing, but the computers likely became infected with generic information-stealing malware.
The company emphasized: “We have no reason to believe this malware is related to Claude, was installed through Claude, or is related to anything you did with Claude.”
The Reddit user who shared the email confirmed that he had downloaded a pirated game.
According to Anthropic, this type of malware typically enters through downloads or malicious applications and steals locally stored information, including browser passwords, login cookies, and credentials for other applications.
Anthropic identified several types of malware, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as a small number of cases involving Atomic Stealer (AMOS) on Mac.
If your computer is affected, Claude will revoke compromised sessions and remove saved payment methods to prevent unauthorized purchases.
Anthropic urged affected users to take basic security measures, including changing their credentials, revoking other sessions, and removing the malware from their computers.
