All incidents

Infostealer malware hijacks Claude AI sessions

malwareopenAug 31, 2026 — Aug 31, 2026
Infostealer malware hijacks Claude AI sessions

ANTHROPIC has warned users of its Claude AI service that infostealer malware has been hijacking active login sessions and draining paid subscriptions according to SecurityWeek. The security team detected the malicious code on compromised Windows and macOS machines, where it stole session tokens without needing passwords. Affected accounts had their sessions terminated, saved payment methods removed and any unauthorized charges refunded as a precaution.

The malware is not a vulnerability in Claude itself but is distributed through unofficial downloads or trojanised applications that masquerade as legitimate software. Once executed it harvests browser cookies and authentication tokens, allowing attackers to replay Claude sessions and bypass multi‑factor authentication. Researchers linked the activity to known infostealer families such as Vidar and RedLine, which are known to exfiltrate credentials from a variety of applications as reported by SecurityAffairs.

No CVE identifier has been assigned because the issue stems from endpoint compromise rather than a flaw in the Claude service. The stolen tokens grant immediate access to the victim's Claude workspace, enabling attackers to query the model, consume usage quotas and potentially expropriate any associated paid plan. Anthropic responded by invalidating the compromised tokens and advising users to verify the integrity of their devices before reconnecting payment methods.

The campaign was first observed on 31 August 2026 and continued through the afternoon, with telemetry showing a spike in anomalous session activity. Although no specific threat actor has been claimed, the timing coincides with a rise in infostealer distribution via fake software cracks and pirated utilities. Anthropic’s precautionary refunds aim to limit financial harm while users clean their systems.

Users should run a full anti‑malware scan with updated signatures and quarantine any detected threats. After confirming the host is clean, they should delete any saved Claude payment information and re‑add it only after verifying the card details. Enabling two‑factor authentication on the Claude account and monitoring the billing dashboard for unexpected charges are also recommended.

Staying with the official Claude client or web interface reduces the risk of trojanised downloads. Keeping operating systems and security tools patched helps block the common infection vectors used by Vidar and RedLine. Organisations are advised to educate staff about the dangers of unofficial software and to enforce endpoint protection policies that block known infostealer indicators.

Intelligence briefing updated Aug 31, 2026

Timeline Coverage

Swipe to explore timeline