<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage-z5ucak5u9" -->

---
title: Anthropic warns infostealer malware is hijacking Claude...
description: Anthropic is alerting affected Claude users that infostealer malware such as Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on Mac, has...
canonical: https://daily.dev/posts/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage-z5ucak5u9
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Anthropic warns infostealer malware is hijacking Claude sessions to drain usage | daily.dev
og:description: Anthropic is alerting affected Claude users that infostealer malware such as Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on Mac, has...
og:url: https://daily.dev/posts/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage-z5ucak5u9
og:image: https://api.daily.dev/og/posts/Z5uCaK5u9.png
og:image:alt: Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

Anthropic is alerting affected Claude users that infostealer malware such as Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on Mac, has stolen active browser login sessions from infected computers, letting attackers hijack Claude accounts and burn through usage without needing passwords or 2FA since sessions were already authenticated. Anthropic says the malware is unrelated to Claude itself, and is responding by signing out affected accounts, removing saved payment methods, and refunding unauthorized charges. Users are urged to change credentials, revoke other sessions, and remove the malware since signing out alone doesn't fix an infected machine.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage>

## Questions this post answers

### Why did my Claude usage limits refill and then drain even though I wasn't using Claude?

Infostealer malware on a computer likely stole an authenticated Claude browser session, and an attacker used that stolen session to access the account and consume usage without needing a password or 2FA. Anthropic has linked these attacks to infostealers including Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on Mac.

_Developers relying on Claude for coding workflows can follow security incidents like this one on daily.dev._

### What should I do if my Claude account was compromised by infostealer malware?

Change credentials, revoke other active sessions, and remove the malware from the infected device, since Anthropic signing an account out of Claude stops the stolen session but does not remove the malware itself. Anthropic is also removing saved payment methods and refunding charges identified as unauthorized for affected accounts.

_Anyone securing AI coding tool accounts can track vendor security advisories like this on daily.dev._

## Similar posts on daily.dev

- ['Claudy Day’ Trio of Flaws Exposes Claude Users to Data Theft](https://daily.dev/posts/claudy-day-trio-of-flaws-exposes-claude-users-to-data-theft-oxmixvsef) · Dark Reading · 8 upvotes · 0 comments
- [Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign](https://daily.dev/posts/threat-actors-abuse-claude-ai-shared-chat-for-clickfix-malvertising-campaign-zdoc6dupj) · Trend Micro · 1 upvotes · 0 comments

---

Tags: [#claude](https://daily.dev/tags/claude), [#anthropic](https://daily.dev/tags/anthropic)

[View this post on daily.dev](https://daily.dev/posts/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage-z5ucak5u9)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Anthropic warns infostealer malware is hijacking Claude sessions to drain usage","url":"https://daily.dev/posts/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage-z5ucak5u9","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage-z5ucak5u9"},"datePublished":"2026-08-30T14:30:48.062Z","dateModified":"2026-08-30T14:31:10.755Z","description":"Anthropic is alerting affected Claude users that infostealer malware such as Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on Mac, has...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/aa05cf1000990b2362b0200a0e58bf09?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/aa05cf1000990b2362b0200a0e58bf09?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage-z5ucak5u9","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"claude,anthropic","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Anthropic warns infostealer malware is hijacking Claude sessions to drain usage"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage-z5ucak5u9#faq","mainEntity":[{"@type":"Question","name":"Why did my Claude usage limits refill and then drain even though I wasn't using Claude?","acceptedAnswer":{"@type":"Answer","text":"Infostealer malware on a computer likely stole an authenticated Claude browser session, and an attacker used that stolen session to access the account and consume usage without needing a password or 2FA. Anthropic has linked these attacks to infostealers including Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on Mac. Developers relying on Claude for coding workflows can follow security incidents like this one on daily.dev."}},{"@type":"Question","name":"What should I do if my Claude account was compromised by infostealer malware?","acceptedAnswer":{"@type":"Answer","text":"Change credentials, revoke other active sessions, and remove the malware from the infected device, since Anthropic signing an account out of Claude stops the stolen session but does not remove the malware itself. Anthropic is also removing saved payment methods and refunding charges identified as unauthorized for affected accounts. Anyone securing AI coding tool accounts can track vendor security advisories like this on daily.dev."}}]}
```

