Anthropic, the company behind the popular Claude AI, has alerted its users to a concerning cybersecurity threat. Infostealer malware is actively targeting Claude accounts, compromising login sessions and illicitly consuming users' premium service allocations.
The company's investigation reveals that pre-existing malware on users' devices is responsible for these attacks, not a vulnerability within Claude itself. These infostealers are designed to covertly harvest data stored by web browsers, including authenticated session cookies. This allows attackers to bypass traditional password protections and even two-factor authentication (2FA), gaining unauthorized access to user accounts.
How Infostealers Compromise Accounts
Unlike phishing or direct password theft, infostealers operate by copying active browser sessions. This means that even if a user's password remains secure, an attacker can effectively 'impersonate' a logged-in user. Once a session is stolen, malicious actors can access the Claude interface, deplete usage credits, and potentially expose personal data linked to the account.
Anthropic has identified several common infostealer malware families involved, including Vidar, LummaC2, StealC, RedLine, and Acreed, primarily affecting Windows users. A smaller number of Mac users have been impacted by Atomic Stealer (AMOS). The malware typically spreads through malicious downloads, such as pirated software, as one affected user reported downloading a pirated game prior to compromise.
Warning Signs and Anthropic's Response
A key indicator of a compromised Claude account is an unexpected and rapid draining of usage limits, even when the legitimate user is not actively interacting with the platform. This sudden, unexplained consumption of credits often signals that a stolen session is being exploited.
In response to confirmed compromises, Anthropic is taking immediate action. The company is forcibly signing out affected users, revoking any stolen sessions, removing saved payment methods, and refunding unauthorized charges. However, Anthropic emphasizes that logging out only stops the stolen session; it does not remove the underlying malware from the infected device.
User Recommendations for Security
To protect their accounts, Anthropic is advising affected users to take several critical steps. It is imperative to change Claude login credentials, revoke all active sessions, and, most importantly, remove the infostealer malware from their devices before logging in again. Users should also maintain robust device security, including up-to-date antivirus software and vigilance against suspicious downloads, especially for accounts linked to payment information or premium AI services.