Anthropic is warning Claude users about a wave of attacks where criminals exploit common infostealer malware to steal login sessions from infected computers, then use those sessions to access accounts and drain paid credits. According to security publication Help Net Security, Anthropic has been proactively contacting affected users since August 30.
Session Theft, Not Password Theft, Bypasses MFA
The key to this attack is that attackers are not stealing passwords but login sessions. These general-purpose malware programs running locally on victims' machines capture browser-stored cookies and session IDs. Since these cookies represent an "already authenticated" state, attackers can replay them to be treated as logged-in users, bypassing multi-factor authentication and accessing accounts without the user's knowledge.
Anthropic said the malware identified in this wave includes Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows, and Atomic Stealer (AMOS) on some Macs. These malware typically enter computers through unofficial downloads or malicious apps, copying browser-stored passwords, login cookies, and other local credentials.
Anthropic Force-Logs Out Users, Issues Refunds, Urges Malware Removal
In response, Anthropic has force-logged out affected users to invalidate stolen sessions, removed stored payment methods from accounts, and refunded charges it determined to be unauthorized. The company also urged affected users to take basic security measures, including changing credentials, revoking sessions on other devices, and removing the malware from their computers.
Anthropic specifically clarified that the malware does not originate from Claude. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to any of your actions on Claude," the company said. In other words, the problem is that users' computers have been infected, not that the Claude platform itself has been compromised.

