Anthropic Warns Claude Users as Infostealer Malware Hijacks AI Sessions

Anthropic Warns Claude Users as Infostealer Malware Hijacks AI Sessions

Anthropic has begun warning some Claude users after detecting suspicious activity linked to infostealer malware capable of stealing active login sessions and using them to access Claude accounts.

The incident highlights an increasingly important cybersecurity challenge as artificial intelligence tools become integrated into everyday business operations: protecting an AI platform is only one part of the security equation. The devices, credentials, sessions, integrations, and workflows surrounding AI systems must also be protected.

According to warnings sent to affected users, attackers have been using commonly available infostealer malware to obtain Claude login sessions stored on compromised computers. Those sessions can then be reused to access accounts and consume Claude usage without necessarily going through the normal authentication process again.

What Happened to Claude Users?

The campaign does not currently appear to be the result of attackers compromising Anthropic’s infrastructure.

Instead, affected computers were reportedly infected with general-purpose information-stealing malware. These tools are designed to quietly collect valuable information stored on a device, including browser passwords, authentication cookies, session information, and credentials belonging to other applications.

A Claude session stored on an infected computer can therefore become one of many credentials collected by the malware.

Once attackers possess a valid authenticated session, they may be able to impersonate the legitimate user without performing a completely new login.

This explains why users could potentially see Claude usage limits unexpectedly decrease even when they were not actively using the service. Anthropic has reportedly responded to detected cases by terminating affected sessions and removing stored payment methods as an additional protective measure.

How Can Attackers Access Claude Without the Password?

The incident demonstrates an important distinction between credential theft and session theft.

Multi-factor authentication provides valuable protection when someone attempts to authenticate with a stolen password. However, an already authenticated browser session is different.

If malware successfully copies valid session cookies or tokens, an attacker may be able to reuse that authenticated state rather than initiating another standard login. As a result, the attacker does not necessarily need to defeat the user’s password or two-factor authentication directly.

This is why session protection has become increasingly important for cloud applications, developer platforms, and AI services.

Which Infostealer Malware Is Involved?

The malware associated with the campaign includes several known information-stealing families affecting Windows systems, including Vidar, LummaC2, StealC, RedLine, and Acreed.

A smaller number of macOS systems were reportedly associated with Atomic Stealer, also known as AMOS.

These are not Claude-specific threats. Infostealers can target a broad range of information stored on compromised computers, which means other browser sessions, cloud applications, email accounts, financial services, developer credentials, and enterprise platforms may also be exposed.

What Should Claude Users Do?

Simply logging out of Claude is not enough if the underlying computer remains infected. A newly created session could potentially be stolen again.

Users who believe their device may be affected should prioritize several actions:

  • Scan and clean the computer using trusted endpoint security tools.
  • Secure the email account associated with Claude and change its password.
  • Terminate existing sessions on important services and review connected devices.
  • Enable multi-factor authentication wherever available.
  • Change credentials for sensitive work, financial, cloud, and developer accounts that may have been stored on the affected system.
  • Review unexpected account activity and payment transactions before adding payment information again.

For organizations, the situation also reinforces the importance of endpoint protection, credential lifecycle management, access controls, session monitoring, and audit visibility around AI services.

What This Means for Enterprise AI Security

AI is quickly moving beyond standalone chat interfaces.

Enterprise AI systems can now connect to email, documents, cloud infrastructure, APIs, developer platforms, ticketing systems, and automated workflows. As those capabilities expand, compromised AI identities or credentials can potentially provide attackers with access to much more than an AI conversation.

Enterprises therefore need security controls around who can access AI systems, which tools AI agents can use, what actions they can execute, how credentials are stored, and how every action can be investigated afterward.

This is where governed AI orchestration becomes increasingly important.

Building a More Governed AI Environment with CommandLyne

CommandLyne is an enterprise AI orchestration platform designed to give organizations greater control over AI agents, models, workflows, integrations, credentials, and operational activity.

Its security architecture includes infrastructure isolation, role-based access control, Google Workspace SSO integration, admin-controlled permissions, and no anonymous access. Deployments can use dedicated Google Cloud infrastructure with isolated runtimes, helping establish stronger boundaries between AI environments.

Sensitive credentials are protected using Google Secret Manager, while keys, tokens, logs, and backup artifacts are encrypted at rest using AES-256. CommandLyne also supports token rotation policies rather than relying on plaintext API keys.

For governance and incident investigation, CommandLyne provides logging across prompts, tool usage, external API calls, and agent activity. Administrators can also apply approval gates to sensitive workflows and terminate unsafe sessions or runaway automations when necessary.

These controls do not replace endpoint protection or prevent an infostealer from infecting an employee’s computer. Instead, they address another critical layer of enterprise AI security: reducing uncontrolled access, protecting AI credentials, restricting execution, and giving administrators visibility into what AI agents are doing.

As AI becomes part of core enterprise operations, security can no longer focus only on the model. Organizations need governed infrastructure around the entire AI ecosystem, from identity and credentials to agents, integrations, workflows, and execution.

Explore how CommandLyne helps enterprises bring security, governance, visibility, and operational control to AI adoption.

"CODIMITE" Would Like To Send You Notifications
Our notifications keep you updated with the latest articles and news. Would you like to receive these notifications and stay connected ?
Not Now
Yes Please

We value your privacy

Codimite uses essential cookies to keep our website secure and functional. With your consent, we also use analytics and marketing cookies to improve your experience and understand website usage.

You can accept all cookies, reject all cookies, or manage your preferences. Learn more in our Privacy Policy.

We use cookies to understand how our website is used. You can or . See our Privacy Policy.