Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
BLUF
Infostealer malware is compromising Claude accounts by hijacking active sessions to drain usage quotas.
NEWS
Anthropic notified users that infostealer infections on endpoint devices are extracting valid session tokens for their AI platform. Attackers utilize these stolen credentials to access accounts and consume paid usage limits without authorization. This incident highlights the risk of session hijacking even when passwords remain secure.
Why I Care
This affects all Claude users with endpoint malware, leading to direct financial loss through drained credits and potential data exposure within chat histories. It underscores that strong passwords are insufficient if session tokens are compromised by local malware.
Next Steps
Users should immediately revoke active sessions in their account settings and run full endpoint scans to remove infostealers. Organizations should enforce multi-factor authentication where possible and monitor usage anomalies for unexpected spikes.
Source: BleepingComputer ·