Anthropic warned Claude users that infostealer malware compromised their computers and stole active login session cookies starting August 30, 2026. These stolen cookies allowed attackers to access accounts without passwords or two-factor authentication, draining victims’ paid usage quotas. The company forcibly signed out all compromised sessions, removed saved payment methods, and refunded unauthorized charges. The malware families identified include Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) on Mac. The infections originated from malicious downloads and compromised software installed by users on their own machines, not from any flaw in Claude or its infrastructure.
Source: Read the original article

