Anthropic disclosed that infostealer malware families including Vidar, Lumma, StealC, RedLine, Acreed, and Atomic Stealer are stealing active browser session cookies from infected Windows and macOS machines, letting attackers hijack logged-in Claude accounts without needing a password or 2FA code. Attackers used the stolen sessions to consume victims’ paid usage and, in some cases, run up unauthorized charges. Anthropic responded by signing out affected sessions, removing stored payment methods, and refunding confirmed fraudulent charges, but noted these account-side fixes do not remove the malware from an infected device.