Anthropic Warns of Infostealer Malware Hijacking Claude Accounts

Anthropic has issued warnings to some Claude users that their personal computers may be infected with infostealer malware capable of stealing login sessions and credentials, according to reports. The warning followed an email shared on Reddit by a user who said they received it from the company, detailing a campaign in which a 'bad actor' used common infostealer malware to steal Claude login sessions from people's computers.

The stolen sessions could be used to access Claude accounts without obtaining the user's password, Anthropic reportedly wrote in the email. The company said that unusual account activity could be a sign of the problem, noting that users who noticed their usage limits suddenly refill and then drain while they were not using Claude were likely victims. "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause," Anthropic reportedly said.

Malware Not Linked to Claude

Anthropic reportedly stressed that the malware was not connected to Claude itself. According to the email, the company said it currently believes the problem was caused by malware already present on affected computers, and that there was no indication that Claude installed the malware or that users caused the infection by using the service. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the company said. Anthropic also said phones and tablets do not appear to have been affected by the campaign.

Company Response and Identified Malware

In response to the security breach, Anthropic has been signing affected users out of their Claude sessions and deleting their saved payment information, as reported by multiple sources. The company's email to affected users stated: "We recently signed you out of Claude and removed the payment method saved on your account." Anthropic has also promised to refund any charges that its investigation finds were unauthorized.

The investigation identified several infostealers used in the campaign, including Vidar, LummaC2 (also known as Lumma), StealC, RedLine, and Acreed on Windows computers, as well as Atomic Stealer (AMOS expedition on a smaller number of Macs. The company has not revealed how many accounts have been affected.

Anthropic's investigation into the matter suggests the issue is a larger endpoint-security problem rather than a breach of its own infrastructure, as reported by one source. The company warned that while account-level measures such as signing out sessions can prevent further misuse of a stolen session, they cannot remove malware from an infected computer. Affected users are urged to scan their computers for malware before continuing to use them, secure the email account connected to Claude, and only add a payment method back to Claude after security steps have been completed.

User Experiences and Recommendations

A Redditor who shared their experience with the issue admitted to downloading a pirated game that contained hidden infostealer malware, and claimed thattwo-factor authentication did not protect them. The same user recounted deploying Claude directly into their computer, which proceeded to root out the malware. A user identifying as a security expert with twenty years of professional experience red-teaming malware recommended wiping the entire computer and starting anew.

Anthropic has not commented publicly beyond the email sent to affected users, which was shared via Reddit. The company's guidance emphasizes caution when downloading software, especially from unofficial sources, to avoid falling victim to such attacks in the future.