Anthropic warns infostealer malware is hijacking Claude sessions
Cybercriminals are using PC infostealer malware to hijack active Claude login sessions and drain user usage limits.

Artificial intelligence pioneer Anthropic has issued a security warning to some Claude users after discovering that infostealer malware on infected personal computers is successfully stealing active login sessions.
According to BleepingComputer, these malicious programs covertly target user devices to harvest active session tokens and authorization data directly from web browsers. This allows attackers to bypass standard login procedures and gain unauthorized entry to accounts without needing the actual passwords.
Once inside, the threat actors leverage the hijacked accounts to consume the victims' allocated usage limits rapidly. This unauthorized exploitation drains the resources and benefits tied to the compromised subscriptions, leaving users with depleted balances and disrupted workflows.
For the broader tech community, including users in Central Asia, this incident underscores the critical importance of endpoint security. As reliance on cloud-based AI tools grows, maintaining clean operating systems, avoiding pirated software, and using robust antivirus solutions are vital to preventing credential theft.
Anthropic is advising affected users to run thorough malware scans on their devices, clear browser session data, and update their account credentials immediately while continuing to monitor and improve platform security measures.



