Anthropic is warning Claude users after cybercriminals used common infostealer malware, including Vidar, LummaC2, and Atomic Stealer, to hijack active login sessions and bypass multifactor authentication. Attackers are using these stolen sessions to burn through paid usage limits. Anthropic has responded by revoking compromised sessions, deleting stored payment methods, and promising refunds. Separately, security researchers identified campaigns distributing malware via fake Claude desktop installers and poisoned SKILL.md configuration files.
Sep 1, 2026 · 1 source
Aug 31, 2026 · 4 sources
Aug 28, 2026 · 1 source
Aug 27, 2026 · 4 sources
Story comments
Loading comments…