Claude Sessions Hijacked by Infostealers
Anthropic is warning some Claude users that infostealer malware has stolen active login sessions, enabling attackers to access accounts and consume paid usage without users’ knowledge. The compromise originates from infected devices rather than a vulnerability in Claude itself.
The campaign reportedly involves Windows malware including Vidar, LummaC2, StealC, RedLine and Acreed, alongside Atomic Stealer targeting some Mac users. These threats operate silently, harvesting credentials, browser information and authenticated sessions.
Session theft is particularly dangerous because attackers may not need passwords or even defeat multi-factor authentication. By stealing an already authenticated browser session, criminals can effectively inherit the user’s trusted access.
Anthropic is responding by revoking compromised sessions, signing affected users out, removing stored payment methods and refunding charges identified as unauthorized. However, session revocation addresses the account compromise, not the underlying endpoint infection.
If malware remains on the device, a newly authenticated session could simply be stolen again. Users therefore need to remove the malware, change credentials and revoke other potentially compromised sessions before safely restoring access.
The incident highlights a broader cybersecurity shift: identity security can no longer stop at passwords and MFA. Once attackers obtain legitimate sessions, detection increasingly depends on behavioral indicators such as unusual activity, abnormal consumption, device changes and geographic inconsistencies.
For enterprises adopting AI platforms, the lesson is significant. Protecting AI accounts requires a layered model combining endpoint security, identity protection, session monitoring and behavioral intelligence. As AI becomes embedded in critical workflows, authenticated sessions themselves are becoming valuable digital assets—and increasingly attractive targets for cybercriminals.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




