Daily Beirut

AI

Claude Users Alerted to Infostealer Malware Targeting Login Sessions

Anthropic has warned affected Claude users that infostealer malware on their Windows computers may have stolen active login sessions, enabling unauthorized access and quota consumption.

··2 min read
Claude Users Alerted to Infostealer Malware Targeting Login Sessions
Share

Anthropic has issued an urgent security alert to certain users of its AI assistant Claude, warning that infostealer malware may be present on their personal computers or laptops.

How Infostealer Malware Operates

Infostealer malware grants attackers access to sensitive user information—including account credentials and login data. In this instance, such malware could also enable unauthorized use of a victim’s Claude account. Anthropic confirmed it sent notifications to multiple Claude users whose devices are suspected of being infected with infostealer software.

These malicious programs can allow attackers to access Claude accounts and consume users’ allocated usage limits. As a protective measure, Anthropic began forcibly signing out affected users from their Claude accounts and removing stored payment methods.

Some impacted users may receive refunds for charges Anthropic deems unauthorized.

Claude Not the Source of the Threat

A Reddit user identified as WorriedAssociate7029 shared an email Anthropic sent them on the ClaudeAI subreddit forum. In the message, Anthropic stated it “recently became aware of a malicious actor” using widely available infostealer malware to steal active Claude login sessions from users’ devices—and then exploiting those sessions to access accounts. The company noted this activity may explain unusual usage patterns observed in affected users’ Claude accounts.

The email further advised users that if their usage limits appeared to reset and were then rapidly exhausted—even while they were not actively using Claude—infostealer malware was likely responsible.

Windows Devices Are the Sole Confirmed Target

Anthropic is investigating the incident but indicated current evidence points exclusively to compromised Windows computers infected with infostealer malware. The company emphasized that smartphones and tablets do not appear to be affected. It also explicitly stated there is no indication the malware is linked to the Claude service itself, was installed via Claude, or resulted from any action taken by users while using the service.

What Data Infostealers Extract

Infostealer malware typically reaches users through unofficial downloads or malicious applications. Once installed, it operates covertly to harvest saved passwords, browser cookies tied to login sessions, and other locally stored application credentials.

The threat extends beyond password theft: collected data can assist attackers in bypassing two-factor authentication and gaining broader access to user accounts. This makes infostealer infections a systemic security risk, potentially exposing numerous accounts and services associated with the compromised device.

Claude Sessions Among Stolen Credentials

Anthropic confirmed that users’ active Claude login sessions were likely among the many data elements harvested by the malware from infected devices. Attackers subsequently identified and reused these stolen Claude sessions to gain account access.

The company specified that the infostealer families identified so far in this campaign include Vidar, LummaC2, StealC, RedLine, and Acreed—all targeting Windows systems.

Add Daily Beirut to your Google News feed to get the latest first.
Share