Anthropic Users Targeted by Infostealer Malware

Anthropic has begun forcibly signing out a number of Claude users and removing the payment method saved on their accounts, after the company discovered that an attacker was using stolen login sessions from victims’ computers to access their accounts and burn through their usage.

Source: https://x.com/IntCyberDigest/status/2093793184518111344?s=20

What happened

According to the notification Anthropic sent to affected users, the company identified a bad actor using infostealer malware — software designed to harvest data saved on a device — to collect Claude login sessions directly from infected computers. Once obtained, these sessions were then used to log into accounts without ever needing a password.

Anthropic stresses that the infection has nothing to do with Claude itself, with anything users did inside the app, or with a breach of the company’s own systems. This is general-purpose malware that typically arrives through an unofficial download or a compromised app, and which quietly collects saved passwords, browser login cookies, and credentials for other locally installed applications. A user’s Claude session was apparently just one of many things swept up in that collection — it appears the attacker only later started picking Claude sessions out specifically from everything harvested and putting them to use.

Based on the information made public, phones and tablets do not appear to be involved — the issue is limited to computers.

The malware families identified

Anthropic named six infostealer families involved in this wave of attacks, split across operating systems:

  • Windows: Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed
  • macOS: Atomic Stealer (AMOS), on a small number of devices

All are well-established malware in the criminal ecosystem — frequently sold as a service (malware-as-a-service) and typically distributed through cracked-software sites, pirated apps, or malicious ads.

Anthropic’s response

In response, the company automatically signed affected accounts out across all devices and deleted the saved payment method, to prevent further unauthorized usage being billed to the victim’s card. Affected users need to log back in and manually re-add their card if they want to keep using a paid plan.

Anthropic recommends that affected users:

  1. Scan the computer used with Claude for malware and remove anything found before using it further.
  2. Use native security tools — Microsoft Defender on Windows, or Apple’s malware-protection guidance on Mac — to check the machine.
  3. Once the malware has been fully removed, change the password on the email account used for Claude, sign out of all other devices, and enable two-factor authentication (2FA).

The company warns that simply signing a user out stops the stolen sessions that are already active, but doesn’t remove the malware from the device — if it’s still installed, the next login session can be stolen just as easily.

Context: attacks on AI-tool users are on the rise

The incident fits a pattern that has become increasingly common through 2026: infostealer campaigns specifically targeting users of AI tools, including Claude Code. Security researchers at firms such as Cyderes and Straiker have documented, in recent months, fake installation pages mimicking the official Anthropic site that deliver an infostealer alongside an apparently successful install — one that steals browser data, crypto wallets, and API keys. Anthropic has repeatedly stressed that its platform itself was not compromised in these campaigns — the brand is simply being impersonated to trick users into infecting their own devices.


Disclaimer: AI-generated commentary (Claude, Anthropic), approved/under editorial supervision — Robert Williams.

Source: International Cyber Digest (@IntCyberDigest) pe X — alerta originală Cyderes — Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer Straiker — Fake Claude Code, Real Malware: Inside the Campaign Targeting AI Developers


Discover more from #News247WorldPress

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading