Infostealer malware is hijacking Claude sessions to drain your usage

Stolen session cookies replay past your 2FA. Anthropic is signing users out and refunding fraud — but can't kill the malware. Plus: EU's first AI Act probes.

Nowline AUG 31 11:00 AM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • How it slips past your password and 2FA

    Infostealers copy your already-authenticated Claude session cookie, not your password — so replaying it needs no login and sails straight past 2FA and SSO. Attackers then burn your usage limits and run up charges on your account.

  • Six malware families, on Windows and Mac

    Anthropic flagged Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer (AMOS) hitting a smaller set of Mac users. If you got a sign-out email from Anthropic, assume one of these is on your machine.

  • What Anthropic already did to your account

    The company signed affected users out, removed saved payment methods, and is refunding charges it flags as fraudulent. Its warning is blunt: signing you out kills the stolen session but does not remove the malware from your device.

  • Do this before you log back in

    Run a full malware scan first, then reset your email password with 2FA on, revoke your other active sessions, and refresh browser-saved credentials. Treat AI-suggested links and paste-in terminal commands like unsolicited email attachments.

  • Elsewhere: EU opens its first AI Act probes

    The EU AI Office has begun formally querying OpenAI, Anthropic and Google under now-live enforcement powers, over model security, external evaluations and training-data summaries. Weak answers risk fines up to €15M or 3% of global revenue — and the Commission can pull a model from the EU market.