Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Vira Manti

Published Aug 30, 2026, 5:46 PM UTC

Source: SecuritySource
- Infostealer malware is swiping active Claude session cookies off infected PCs, letting attackers ride someone else's login and burn through their usage quota. Anthropic's flagged affected users — so if you got that notice, your machine was already compromised before Claude ever entered the picture. Stop kidding yourself: the model didn't leak, your OPSEC did. Victims lose paid usage and API credits; anyone sharing a compromised machine inherits the blast radius. Check the seals — run a full malware sweep, revoke all active sessions, rotate credentials, and enable hardware-key 2FA. Treat session tokens like unsealed cargo: if you don't know where they've been, assume they're already in someone else's relay window. Delivery signature applied.