According to bleepingcomputer, Anthropic has warned some Claude users that malware designed to steal information has stolen active Claude login sessions from their computers, allowing attackers to access accounts and steal usage data. In an email to affected users, Anthropic wrote, "We recently discovered that criminals have used common information-stealing malware to steal Claude login sessions from users' computers, then used these sessions to access Claude accounts and steal their usage data."

Session tokens have been hijacked, changing passwords may not help

The scary part about this type of attack is that it bypasses the password itself: information-stealing trojans specifically target cookies and session tokens stored in the browser, and once attackers obtain the token, they can directly impersonate the user's identity to access the account without needing to enter the account password or two-factor verification. For users who integrate Claude into their daily workflow and store code and business information, the leak is not just chat records, but also usage data and potentially linked payment information.

Currently, Anthropic is forcibly logging affected users out of their Claude accounts, removing saved payment methods, and refunding fees it deems unauthorized. The official also urges users to implement several basic security measures: changing account credentials, revoking other still-active sessions, and thoroughly removing malware from their computers — the order is equally important, first remove the malware before changing the password, otherwise the new password might be stolen again.

This incident also reminds AI tool users: the security of the local terminal is an integral part of using AI services. Session hijacking is not a unique risk for Claude. Regularly clearing browser credentials, being vigilant about unusual logins, and promptly revoking idle sessions are the lowest-cost self-protection actions.