Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Summary
Anthropic warns that infostealer malware (software that steals information from infected computers) on users' PCs has stolen active Claude login sessions, allowing attackers to access accounts and use up their API credits without permission. The malware typically arrives through pirated downloads or malicious apps and captures browser passwords and login cookies, which attackers then use to hijack Claude accounts. Anthropic is signing affected users out, removing saved payment methods, and refunding unauthorized charges.
Solution / Mitigation
Anthropic is revoking compromised sessions and removing saved payment methods to prevent further unauthorized access. The company urges affected users to change their credentials, revoke other sessions, and remove the malware from their computers. However, Anthropic notes that 'Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware. If it's still on your computer, your next login session could be stolen the same way,' emphasizing that users must actively remove the malware from their systems.
Classification
Affected Vendors
Related Issues
Original source: https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/
First tracked: August 30, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%