Anthropic has warned that a bad actor is using common infostealer malware to steal Claude login sessions from users' computers, then using those sessions to access accounts and consume usage. The company is sending emails to affected users, signing them out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized.
"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic said in an email shared on Reddit by an affected user.
According to Anthropic, the malware copies authenticated browser sessions, bypassing password and two-factor authentication. The company emphasized that the malware is general-purpose and unrelated to Claude itself: "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude."
The malware typically arrives through downloads or malicious apps and collects browser passwords, login cookies, and credentials. The affected Redditor confirmed they downloaded a pirated game, which likely caused the infection.
Anthropic identified multiple types of infostealers involved, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer (AMOS) on a small number of Macs.
The company warned affected users that signing them out stops the stolen sessions but does not remove the malware. It urged users to change credentials, revoke other sessions, and remove the malware from their PCs.