🤖 Anthropic flags Claude session hijacks by infostealer malware
Anthropic says some Claude users had active login sessions stolen by infostealer malware, letting attackers access accounts and burn through usage quotas. The company is signing out affected users, removing saved payment methods, and refunding unauthorized charges. Malware families named include Vidar, LummaC2, StealC, RedLine, Acreed, and a smaller number of AMOS cases on macOS, outlined in the Anthropic warning.
The key point is session theft, not password compromise alone: copied authenticated browser sessions can bypass normal login friction, including 2FA. Revoking Claude access contains account abuse, but does not remove the underlying infostealer from the host.
🛰️ Open sources - closed narratives
@sitreports

August 31, 2026 121 1