Infostealer Malware Hijacks Claude Sessions, Draining User Limits

Infostealer Malware Hijacks Claude Sessions, Draining User Limits

First seen 31 Aug 2026, 03:47 UTC BleepingcomputerXenospectrumFirstpostAiweekly.Cosupport.claude.com 62.2

Article Content

Browse articles
ThreatCluster

Anthropic has alerted Claude users that infostealer malware has stolen their active login sessions, allowing attackers to access accounts and consume usage limits. The malware, identified as Vidar, LummaC2, StealC, RedLine, and Atomic Stealer (AMOS), targets Windows and Mac systems. Affected users are being signed out, and their payment methods are being removed. Anthropic has not disclosed the number of impacted users or the timeline of the incident. The company emphasizes that the malware is not related to Claude itself but is instead obtained through malicious downloads or applications. Users have reported unusual usage patterns, such as limits resetting and rapidly depleting. Anthropic is refunding unauthorized charges and advising users to clean their infected devices. The situation highlights the risks associated with stolen authenticated sessions.

Key Points: • Infostealer malware has compromised Claude user sessions, leading to unauthorized usage. • Anthropic is revoking sessions and refunding affected users, but malware remains on infected devices. • The malware is not linked to Claude but is common across various platforms.

Timeline

2026-08-30
BleepingComputer reports on session hijacking
Anthropic notifies users about infostealer malware stealing Claude sessions, leading to unusual usage patterns.
BleepingComputer
2026-08-31
Anthropic issues user advisory
Anthropic alerts Claude users about compromised sessions and initiates account security measures.
Firstpost
2026-08-31
Multiple articles confirm incident details
Various news outlets report on the incident, corroborating Anthropic's findings and user alerts.
Xenospectrum