Anthropic 警告部分 Claude 用户:信息窃取木马劫持登录会话
Anthropic 已向部分受影响用户发送定向安全邮件,称攻击者正从感染了常见信息窃取木马的电脑中盗取现有 Claude 登录会话,再利用这些会话进入账户并消耗用户额度。邮件副本显示,这类木马会收集浏览器密码、登录 Cookie 和其他本地凭证;被点名的家族包括 Windows 上的 Vidar、LummaC2、StealC、RedLine、Acreed,以及少量 macOS 设备上的 Atomic Stealer。
公司对识别出的账户撤销了现有会话、移除保存的支付方式,并表示将退还其确认的未授权费用;原有订阅仍可继续使用。Anthropic 同时提醒,退出 Claude 只能阻止被盗会话继续使用,不能清除终端上的木马,用户仍需检查设备、修改相关密码并撤销其他服务的可疑会话。
现有材料把事件归因于用户终端上的通用木马,而不是 Claude 安装包或 Anthropic 基础设施。已确认的直接影响是账户额度被消耗,以及部分用户出现额外用量费用;公开材料没有给出受影响账户数量,也没有确认聊天、文件、API 密钥或支付卡号被窃取。
BleepingComputer:
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/
The Register:
https://assets.theregister.com/2026/08/31/20264/?td=keepreading

BleepingComputer
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage.
1September 1, 2026 251 1