Anthropic Warns Claude Users of Infostealer Malware Infections
Anthropic has alerted Claude users to a campaign involving infostealer malware that allowed attackers to steal login sessions and drain Claude account usage. The malware, including Vidar, Lumma, and others, was spread through unofficial downloads and malicious apps, leading to account compromise and unauthorized charges. Anthropic has taken steps to mitigate the damage by signing out compromised sessions and removing saved payment methods.
Anthropic has warned Claude users about a campaign involving infostealer malware that compromised user accounts and drained Claude account usage. The company detected that malicious software, including Vidar, Lumma, StealC, RedLine, and Acreed, was installed on affected computers. This malware quietly copied saved passwords, browser login cookies, and credentials for other local applications.
Anthropic believes a threat actor subsequently began selecting the stolen Claude sessions from this harvested data and using them to access accounts. Users who saw their usage limits appear to refill and then drain without actively using Claude were told this was the likely cause.
The company responded by signing out the affected sessions and removing saved payment methods from affected accounts to prevent further unauthorized charges. Anthropic also noted that it refunded any Claude charges it identified as unauthorized.
Victims of this campaign have been advised to only re-add a payment method after ensuring that all malware has been removed from their computers. The malware was spread through unofficial downloads and malicious apps, and it is a general-purpose infostealer, not specifically tied to Claude itself.
Anthropic emphasized that it is actively monitoring for further signs of account misuse and may sign users out again if necessary.