<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/infostealer-malware-is-hijacking-claude-sessions-to-burn-through-users-paid-usage-ribqubb3t" -->

---
title: Infostealer malware is hijacking Claude sessions to burn...
description: Anthropic is alerting Claude users that infostealer malware families - Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on Mac - are...
canonical: https://daily.dev/posts/infostealer-malware-is-hijacking-claude-sessions-to-burn-through-users-paid-usage-ribqubb3t
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Infostealer malware is hijacking Claude sessions to burn through users&#x27; paid usage | daily.dev
og:description: Anthropic is alerting Claude users that infostealer malware families - Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on Mac - are...
og:url: https://daily.dev/posts/infostealer-malware-is-hijacking-claude-sessions-to-burn-through-users-paid-usage-ribqubb3t
og:image: https://api.daily.dev/og/posts/RIbQubb3T.png
og:image:alt: Infostealer malware is hijacking Claude sessions to burn through users&#x27; paid usage
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Infostealer malware is hijacking Claude sessions to burn through users' paid usage

**[Collections](https://daily.dev/sources/collections)** · 1 min read · 1 upvotes · 1 comments

## Summary

Anthropic is alerting Claude users that infostealer malware families - Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on Mac - are stealing authenticated browser sessions from infected machines, letting attackers hijack Claude accounts and burn through paid usage without needing passwords or bypassing 2FA. Anthropic clarifies this is not a Claude vulnerability but a compromise of the underlying machine. For affected accounts, Anthropic is signing users out, removing saved payment methods, and refunding unauthorized charges. Users are advised to run a full malware scan and remove the infection first, then change credentials, then revoke other sessions - in that order, since resetting credentials before cleaning the machine just leads to them being stolen again.

## Content

Anthropic is warning affected Claude users that infostealer malware has been stealing active browser sessions from infected machines, letting attackers hijack accounts and drain usage limits without ever needing a password or bypassing two-factor authentication. Because the sessions were already authenticated, the stolen cookies are enough to get in.

The malware families involved include Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer on Mac. Anthropic is clear that none of this is a Claude vulnerability - the malware operates entirely outside of Claude itself, compromising the underlying machine and lifting session tokens from the browser.

For affected accounts, Anthropic says it's signing users out, removing saved payment methods, and refunding unauthorized charges.

If you think you're affected, the important thing to understand is that signing out alone doesn't fix anything. The malware is still on the machine. The actual steps worth taking:

- Run a full malware scan and remove the infection first
- Change your credentials after the machine is clean
- Revoke any other active sessions

Doing those in the wrong order just means fresh credentials get stolen again.

## Questions this post answers

### Can infostealer malware hijack my Claude account even with two-factor authentication enabled?

Yes, because the malware steals already-authenticated browser session cookies rather than credentials, so it bypasses the need for a password or two-factor authentication entirely. Malware families like Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer on Mac, are behind these session thefts targeting Claude users.

_Developers relying on AI coding tools can follow security incidents like this on daily.dev to stay ahead of account-hijacking threats._

### What should I do if my Claude account was compromised by infostealer malware?

Run a full malware scan and remove the infection from the machine first, then change credentials, then revoke any other active sessions - in that exact order. Changing credentials before cleaning the machine just results in the new credentials being stolen again, since the malware is still active and can grab fresh session tokens.

_Anyone hardening their AI tool usage against credential theft can track incident response guidance like this on daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@wxtx** · 0 upvotes

> Good to know.

## Similar posts on daily.dev

- ['Claudy Day’ Trio of Flaws Exposes Claude Users to Data Theft](https://daily.dev/posts/claudy-day-trio-of-flaws-exposes-claude-users-to-data-theft-oxmixvsef) · Dark Reading · 8 upvotes · 0 comments
- [Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign](https://daily.dev/posts/threat-actors-abuse-claude-ai-shared-chat-for-clickfix-malvertising-campaign-zdoc6dupj) · Trend Micro · 1 upvotes · 0 comments

---

Tags: [#claude](https://daily.dev/tags/claude), [#anthropic](https://daily.dev/tags/anthropic)

[View this post on daily.dev](https://daily.dev/posts/infostealer-malware-is-hijacking-claude-sessions-to-burn-through-users-paid-usage-ribqubb3t)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Infostealer malware is hijacking Claude sessions to burn through users' paid usage","url":"https://daily.dev/posts/infostealer-malware-is-hijacking-claude-sessions-to-burn-through-users-paid-usage-ribqubb3t","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/infostealer-malware-is-hijacking-claude-sessions-to-burn-through-users-paid-usage-ribqubb3t"},"datePublished":"2026-08-31T16:08:51.228Z","dateModified":"2026-08-31T16:09:29.228Z","description":"Anthropic is alerting Claude users that infostealer malware families - Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomic Stealer on Mac - are...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/11dcbd434420e2a304f2cd1471de90a2?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/11dcbd434420e2a304f2cd1471de90a2?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/infostealer-malware-is-hijacking-claude-sessions-to-burn-through-users-paid-usage-ribqubb3t","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"claude,anthropic","timeRequired":"PT1M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Infostealer malware is hijacking Claude sessions to burn through users' paid usage"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/infostealer-malware-is-hijacking-claude-sessions-to-burn-through-users-paid-usage-ribqubb3t","comment":[{"@type":"Comment","text":"Good to know.","datePublished":"2026-08-31T18:10:34.172Z","url":"https://daily.dev/posts/RIbQubb3T#c-y1kkereCo","author":{"@type":"Person","name":"WojtekXTX","url":"https://daily.dev/wxtx","image":"https://media.daily.dev/image/upload/s--slav3kNg--/f_auto/v1788199427/avatars/avatar_y6NTB6llakYmLSelD0bZh?_a=BAMAMicg0"}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/infostealer-malware-is-hijacking-claude-sessions-to-burn-through-users-paid-usage-ribqubb3t#faq","mainEntity":[{"@type":"Question","name":"Can infostealer malware hijack my Claude account even with two-factor authentication enabled?","acceptedAnswer":{"@type":"Answer","text":"Yes, because the malware steals already-authenticated browser session cookies rather than credentials, so it bypasses the need for a password or two-factor authentication entirely. Malware families like Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer on Mac, are behind these session thefts targeting Claude users. Developers relying on AI coding tools can follow security incidents like this on daily.dev to stay ahead of account-hijacking threats."}},{"@type":"Question","name":"What should I do if my Claude account was compromised by infostealer malware?","acceptedAnswer":{"@type":"Answer","text":"Run a full malware scan and remove the infection from the machine first, then change credentials, then revoke any other active sessions - in that exact order. Changing credentials before cleaning the machine just results in the new credentials being stolen again, since the malware is still active and can grab fresh session tokens. Anyone hardening their AI tool usage against credential theft can track incident response guidance like this on daily.dev."}}]}
```

