Claude accounts hijacked as infostealers bypass MFA

Anthropic is warning Claude users that commodity infostealer malware is hijacking authenticated browser sessions, burning paid usage and bypassing MFA controls[1][2][6][8]. Affected customers received emails explaining that attackers are using stolen login cookies to access existing sessions rather than guessing passwords or intercepting one-time codes[1][3][8]. Because the stolen sessions are already validated, traditional controls such as strong passwords, two-factor authentication and single sign-on provide no protection once the endpoint is compromised[2][6].

The campaign leverages well-known information-stealing malware families, including Vidar, LummaC2, StealC, RedLine, Acreed on Windows and Atomic Stealer on a smaller number of macOS devices[1][2][5][6]. These infostealers typically arrive via unofficial downloads, cracked software or malicious apps, then quietly harvest saved passwords, browser login cookies, crypto wallet data and other credentials from infected machines[1][4][11][14]. Investigators say threat actors are now sifting through those dumps to pick out Claude sessions specifically and use them to log in as victims without needing any direct access to their credentials[1][2][3][8]. None of the reporting so far points to a vulnerability in Anthropic’s infrastructure itself; instead, the activity is described as abuse of stolen browser session tokens on already-compromised endpoints[1][5][6].

For paying customers, the financial impact can be significant because Claude’s subscription tiers include usage-based credits that can be topped up automatically when balances run low[3]. If a hijacked account has prepaid credits or auto-reload enabled, an attacker can exhaust the included allowance, consume any additional credits and potentially trigger further purchases, all charged to the legitimate user[3][6]. Researchers note that criminals’ primary motive appears to be mining high-capacity AI access for free, but stolen accounts and any data exposed in chats could also feed fraud, social engineering or follow-on compromises in corporate environments[3][6][9]. Anthropic has previously disclosed disrupting cybercriminal misuse of its tools, including campaigns involving large-scale data theft and even AI-orchestrated espionage, underscoring why adversaries value access to capable models[9][10].

The warning lands amid a broader surge in attacks abusing interest in Anthropic’s developer tooling, particularly the Claude Code CLI and related repositories[11][12][14]. In April, researchers at Zscaler and others documented fake GitHub projects and installer packages masquerading as Claude Code leaks that in reality dropped the Vidar infostealer alongside a proxy tool called GhostSocks[11][14][15]. Separate analysis from Cyderes detailed SEO-poisoned spoof sites that tricked first-time Claude Code users into running a multi-stage script which ultimately deployed a reflective .NET infostealer and exfiltrated credentials to attacker-controlled infrastructure[4][13]. Those reports emphasize that Anthropic’s official download channels were not compromised; instead, its brand and tooling were impersonated to target developers curious about leaked or unofficial builds[11][13][15].

In response to the latest session-hijacking activity, Anthropic is revoking compromised Claude sessions, removing stored payment methods from affected accounts and refunding charges it can verify as unauthorized[1][3][6][8]. The company urges users to fully disinfect any systems used to access Claude before logging in again, including scanning for malware, removing infostealers and installing up-to-date real-time protection to block reinfection[3][7][8]. After cleanup, customers are advised to secure the email accounts tied to Claude by changing passwords, signing out of other devices and enabling two-factor authentication, then updating sensitive credentials stored in the browser, monitoring payment card statements and only then re-adding billing details to their AI subscription[3][7][8]. Users who continue to see unexplained usage spikes or charges after following those steps are directed to contact Anthropic’s safety team for investigation and potential remediation[3][7][8].

References

  1. Anthropic Warns Claude Users of Infostealer Malware …
  2. Infostealer malware is hijacking Claude sessions to burn…
  3. Infostealers Hijack Claude Browser Sessions to Abuse AI Usage
  4. Fake Anthropic Sites Deliver Fileless Infostealer to Claude …
  5. Anthropic cracks down on hijacked user accounts mining …
  6. Infostealer Malware Bypasses MFA to Hijack Claude Accounts
  7. Anthropic locks out Claude users after infostealers hijack …
  8. Anthropic Warns Hackers Are Stealing Claude Sessions To …
  9. Detecting and countering misuse of AI: August 2025
  10. Disrupting the first reported AI-orchestrated cyber espionage campaign
  11. Claude Code leak used to push infostealer malware on …
  12. Your .env File Is Why the Claude Code Attack Worked
  13. Fake Claude Code Installer Drops Infostealer
  14. Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads
  15. Be careful what you click – hackers use Claude Code leak to push …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply