The Infostealer Ecosystem Just Added Your Claude Account
Anthropic is emailing affected users to say their Claude sessions were harvested by commodity malware and reused to burn paid usage — and to warn them that signing them out does not remove the malware
On Aug 30, BleepingComputer reported that Anthropic is sending direct emails to affected Claude users warning them that a "bad actor" has been pulling active Claude login sessions out of commodity infostealer inventory and reusing them to sign into accounts and consume their paid usage. The vendor notice surfaced publicly through an affected user's r/ClaudeAI post titled "Thank you, Anthropic (really)."
Anthropic's language, quoted in the BleepingComputer piece, is precise about what happened and what it did not:
"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage."
And, notably:
"We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude."
What this is, and what it is not
This is not a Claude-side vulnerability. It is the commodity infostealer ecosystem — Anthropic names Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs — being explicitly reoriented to include AI-agent session tokens in the credential haystack it already collects.
The chain is short:
- A user's machine gets compromised by a general-purpose infostealer, usually through a pirated download or a malicious app. (The user who shared Anthropic's email publicly said the vector for their case was a pirated game.)
- The infostealer copies the already-authenticated browser session — cookies plus local credentials — the same way it copies everything else.
- Downstream, an actor pulls the Claude sessions out of the collected inventory and signs into Claude accounts with them.
- Because the session cookie is already post-authentication, the attacker does not go through the password prompt or the 2FA challenge.
The monetization is inference. The attacker's terminal action is not exfiltrating chats or hijacking a workflow. It is running paid inference on someone else's account until the quota is spent. Anthropic's own Aug 30 email gives users the diagnostic tell in plain language: "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause."
Palo Alto Networks Unit 42 has been tracking a broader token-jacking trend all year, describing the same economic logic: premium pricing on scarce AI processing power means stolen API access is quick, easy profit for attackers. This is the consumer-account, browser-session variant of the same market.
What Anthropic is doing about it — and what it is telling users it cannot do
The vendor response set, per the BleepingComputer coverage, is: sign affected users out of Claude, remove saved payment methods to prevent unauthorized purchases, refund charges Anthropic identifies as unauthorized, and email the user.
That is a substantive posture. Treating AI-inference session cookies as a first-class incident-response artifact class — on the same tier as saved card credentials — is not something most vendors have done publicly before.
But the email includes a sentence that is worth reading twice:
"Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware. If it's still on your computer, your next login session could be stolen the same way."
That is the vendor being honest about the shape of the problem. Anthropic can revoke today's session and refund today's charges. It cannot reach the endpoint that opened the window. Without an endpoint-side control — real infostealer removal on the user's machine — the exposure re-opens on the very next sign-in.
Why this matters beyond the immediate campaign
Two things fall out that are worth carrying forward.
First, AI-agent session tokens are now a monetizable haul for the same infostealer supply chain that has been targeting bank sessions and crypto wallets for years. Vidar, LummaC2, StealC, RedLine, Acreed, AMOS — these are commodity families in the pirated-installer distribution ecosystem, and Anthropic just publicly confirmed that at least one downstream actor is filtering their haul specifically for Claude cookies. The other paid-AI vendors are in the same position; there is no reason to expect the filter stops at one product.
Second, the incident tightens the argument for treating an AI account as an active runtime rather than a passive login. The observable that catches this campaign after the fact — "inference is happening on this account, but the account owner is not driving the tool" — is the same observable that catches a compromised API key, a leaked service credential, or an in-app prompt-injection hijack. The account is doing work that no user on the far side of it authorized. Vendor-side session revocation closes today's window on that behavior. The account-side behavioral gap that lets an unattended session run inference undetected is the one that has to be closed at the runtime tier.
The takeaway
Anthropic did the right thing here. The vendor detected a monetization pattern, warned affected users directly, refunded unauthorized charges, and was candid that its remediation stops at the browser boundary.
The market fact behind the disclosure is bigger than one vendor. The commodity infostealer supply chain now has AI accounts on its list. Every paid-AI login sitting in a browser is one machine compromise away from being someone else's inference quota.
Signing users out is the vendor's move. Removing the malware and watching the account for post-compromise inference activity are the moves that have to happen on the runtime side.
SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.