Anthropic has alerted affected Claude users that infostealer malware on their computers has compromised login sessions, enabling attackers to access accounts and consume usage credits without needing passwords or two-factor authentication. The company is signing out compromised users, removing saved payment methods, and refunding unauthorized charges. Anthropic identified multiple malware variants, including Vidar, LummaC2, StealC, and RedLine, on Windows systems, and emphasized that the malware originated from user-installed software unrelated to Claude itself. Users are advised to remove the malware from their devices, since signing out alone does not eliminate the underlying infection.
