Anthropic Links Claude Session Theft to Infostealer Malware
An affected Claude user has shared a warning from Anthropic stating that infostealer malware can steal active Claude login sessions from infected computers. Attackers can reuse these sessions to access accounts and consume available usage without completing the normal sign-in process again.
The report does not indicate a vulnerability or breach in Claude’s infrastructure. Instead, it highlights a broader security problem: once malware compromises an endpoint, an authenticated session can become as valuable as a password and may provide access without triggering a new multi-factor authentication challenge.
What Did Anthropic Tell the Affected User?
An affected Claude user shared Anthropic’s warning on Reddit after malware compromised data stored in their browser. The user said the attacker obtained Chrome credentials, cookies, and session information, allowing access without a new two-factor authentication challenge. The attempt to misuse the user’s Claude account was unsuccessful.

Anthropic warning shared by an affected Claude user after infostealer malware stole active login sessions. (Reddit)
Anthropic explained in the warning that the malware was not related to Claude, installed through Claude, or connected to anything the user had done with the service. The user later said the infection originated from a cracked game, suggesting that the Claude session was only one of several valuable items taken from the compromised device.
Anthropic signed the user out to invalidate the stolen session. However, the company warned that signing out would not remove the malware itself. If the device remained infected, the malware could steal another session when the user logged in again.
How Can a Stolen Session Bypass MFA?
An infostealer can copy browser cookies and other session data after a user has successfully authenticated. If a service continues to accept the stolen session, the attacker may not need the account password or a new MFA code because the session already represents an authenticated state.
This does not mean the malware defeated MFA itself. Instead, it compromised the endpoint and reused a post-authentication artifact. Changing the password may also be insufficient if existing sessions remain valid or the malware steals the replacement session after the user signs in again.
Why Stronger Authentication Does Not Fully Solve Session Theft
Passkeys and phishing-resistant MFA can prevent attackers from stealing or replaying login credentials, but they do not necessarily protect a session that has already been authenticated. If malware controls the endpoint and extracts a valid session cookie, the attacker may enter through the existing session rather than the login process.
This makes endpoint security part of identity security. Strong authentication reduces account takeover risk, but it must be supported by session controls, device monitoring, and the ability to invalidate active sessions quickly.
Why Is the Risk Broader Than Claude Usage?
Infostealers rarely collect only one type of information. They commonly target browser passwords, login cookies, autofill data, financial information, cryptocurrency wallets, and credentials associated with other applications. A stolen Claude session may therefore indicate a much broader endpoint and identity compromise.
Developer workstations deserve particular attention because they may also contain source code, cloud credentials, SSH keys, package-registry tokens, CI/CD access, and other sensitive data. Defenders should investigate everything accessible from the infected browser profile and device instead of treating unexpected Claude usage as an isolated account or billing issue.
What Should Affected Users and Defenders Do?
- Isolate and clean the device: Disconnect the affected system where appropriate and use EDR or trusted security tools to investigate and remove the infostealer before signing in again.
- Revoke active sessions: Sign out of Claude on all devices and invalidate other browser and application sessions that may have been exposed.
- Rotate credentials from a clean device: Change affected passwords and rotate API keys, cloud credentials, developer tokens, and other secrets stored on the compromised system.
- Review account activity: Examine Claude usage and billing information, then review identity, cloud, source-code, email, and SaaS logs for suspicious access.
- Remove untrusted software: Delete pirated or unapproved applications and verify that users obtain software only through official distribution channels.
- Monitor related exposure: Watch for credentials from the affected device appearing in stealer logs or other cybercriminal data sources.
What Could an Attacker Access Through a Claude Session?
The potential impact may extend beyond consumed usage. Depending on the account and its permissions, a hijacked session could expose previous conversations, uploaded files, projects, organizational resources, or information entered during coding and research tasks.
The exact exposure depends on the account type, enabled features, and access rights. Organizations should therefore determine what the affected user could access through Claude at the time of compromise and include that information in the incident scope.
Anthropic confirms that Claude for Work accounts can contain conversations, uploaded files, and usage information. You can link “conversations, uploaded files, and usage information” to Anthropic’s account-data guidance.
How Can SOCRadar Support Detection?
SOCRadar Dark Web Monitoring can help identify credentials and other information exposed through infostealer logs, while Digital Risk Protection can help detect impersonating domains and malicious content targeting tools used by the organization. Threat intelligence can provide additional context about the malware, infrastructure, and campaigns associated with the exposed data.
These capabilities complement endpoint detection and identity monitoring. External intelligence cannot confirm whether a live Claude session was taken from a particular device, so defenders still need to investigate the endpoint, revoke sessions, rotate exposed credentials, and review account activity.
Conclusion
This case points to an endpoint and session-security problem rather than a breach of Claude’s infrastructure. It demonstrates how attackers can reuse post-authentication data even when an account is protected by a strong password and MFA.
Organizations should treat unexpected Claude usage as a possible sign of broader infostealer activity. Clean the affected device, revoke active sessions, rotate exposed secrets, and investigate other accounts accessible from the same browser profile or workstation.

