Anthropic has warned Claude users that threat actors are using common infostealer malware—including Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer—to hijack active browser session cookies. This technique allows attackers to bypass passwords and multi-factor authentication to drain victims' paid usage quotas. Anthropic is responding by terminating compromised sessions, removing saved payment methods, and refunding unauthorized charges, but warns that users must fully remove the malware from their devices to prevent immediate reinfection.
Sep 29, 2026 · 14 sources
Sep 29, 2026 · 13 sources
Sep 29, 2026 · 13 sources
Sep 29, 2026 · 13 sources
Story comments
Loading comments…