Claude Users Targeted by Infostealer Malware Campaign
Infostealer malware infections compromised user accounts on AI platform Claude in August 2026. The attackers used malicious downloads and compromised software applications to infiltrate users' computers, stealing active login session cookies that gave them access to user accounts.
Anthropic, the company behind Claude, discovered the breach through unusual usage patterns on their accounts. They quickly responded by forcibly signing out all compromised sessions, stripping saved payment methods from affected accounts, and issuing refunds to users who incurred unauthorized charges.
The malware families involved in this campaign include Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer on Mac devices. These infostealers are designed to harvest browser data, crypto wallet credentials, and session tokens, making it possible for attackers to hijack user sessions without needing a password or cracking two-factor authentication.
The campaign is distinct from other security concerns surrounding AI platforms in 2026, with some users adopting browser-level protections like Google Chrome's Device Bound Session Credentials to prevent similar attacks.