Anthropic’s Claude AI platform has become an active target for cybercriminals, with two distinct attack chains now confirmed to be stealing credentials, hijacking paid usage, and reinfecting devices even after cleanup.
The company has begun signing out compromised accounts, stripping saved payment methods, and issuing refunds as it works to contain the damage.
According to Anthropic’s own advisory, infostealer malware families including Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows, along with Atomic Stealer on macOS, have been quietly copying saved passwords, browser cookies, and locally stored credentials from infected machines.
Because these tools steal already-authenticated session cookies rather than passwords, the theft bypasses two-factor authentication and single sign-on entirely, letting attackers replay a victim’s Claude session and burn through paid usage without ever logging in themselves. Anthropic says it detected the pattern after noticing usage limits being refilled and then drained while account owners were inactive.
A separate but related threat, tracked by security firm Huntress under the name FakeAgent, shows how attackers weaponized Claude’s own infrastructure.
Between July 21 and July 22, 2026, victims searching Bing for the “Claude desktop app” were served sponsored ads pointing to a malicious public Claude Artifact hosted directly on the legitimate claude.ai domain, inheriting its SSL certificate and search authority.
Clicking the fake installer, disguised as ClaudeDesktop.exe, triggered DLL sideloading through a tampered libcef.dll paired with a repurposed JetBrains helper binary, ultimately deploying SectopRAT, a .NET remote access trojan that harvests browser credentials, credit card data, cookies, and files.
Huntress confirmed at least 29 organizations were compromised in just two days, with the malicious page racking up roughly 7,100 downloads before Anthropic removed it.
A newer persistence trick has also emerged: poisoned SKILL.md files, the documentation-style configuration files used by Claude’s agent skills. Attackers disguise malicious instructions as ordinary style-guide notes; when Claude loads the file, hidden commands silently re-download the infostealer and harvest credentials, meaning the malware can survive even a full operating system reinstall if the tainted file is reintroduced.
One Web3 founder reported nearly losing control of crypto wallets after a Claude chat suggested a terminal command that executed instantly and pulled in the payload.
In response, Anthropic has signed out affected sessions, removed stored payment methods to block further unauthorized charges, and refunded confirmed fraudulent transactions.
The company stressed that these account-side fixes do not remove malware from an infected device, so a freshly created session could be stolen again on next login.
Security researchers recommend running a full malware scan before logging back into Claude, resetting the email password tied to the account with two-factor authentication enabled, updating any credentials saved in browsers, and treating AI-suggested links or terminal commands with the same scrutiny as unsolicited email attachments.
Sandboxing AI agent environments and auditing SKILL.md or similar configuration files for hidden instructions are also advised for organizations deploying Claude at scale.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts appeared first on Cyber Security News.
