Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Anthropic disclosed that commodity infostealers — Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, Atomic Stealer on a handful of Macs — are lifting Claude web session cookies off infected machines and replaying them to drain victims' usage quotas, no credentials needed. Signing out kills the stolen session but not the malware still sitting on the box, so the same account gets re-harvested on next login; it's the same infostealer-to-account-takeover chain that's been feeding this month's ClickFix and fake-Claude-Code-installer campaigns, just pointed at AI service billing instead of crypto wallets. If engineers run Claude on a machine with any history of stealer infection, rotate credentials and revoke sessions — don't just log out.