Anthropic is warning some Claude users that infostealer malware on their computers has stolen active Claude login sessions, according to BleepingComputer. The report says attackers used those sessions to access Claude accounts and consume the users’ available usage. The warning comes from an Anthropic email sent to an affected user and shared on Reddit, according to BleepingComputer. In that notice, Anthropic said a bad actor was using common infostealer malware to take Claude login sessions from people’s computers and then use those sessions inside Claude accounts. Anthropic reportedly told users that if their Claude usage limits appeared to refill and then drain without their activity, this was likely the cause. The important technical detail is that the incident is not described as a breach of Claude itself. BleepingComputer reports that Anthropic told affected users it had no reason to believe the malware was related to Claude, installed through Claude, or connected to anything the users did in Claude. Instead, Anthropic said the computers were likely already infected with general-purpose infostealer malware. That distinction matters because infostealers often target locally stored secrets rather than attacking a service directly. According to the report, Anthropic said the malware typically arrives through downloads or malicious apps and can collect browser passwords, login cookies, and credentials for other applications. BleepingComputer notes that an attacker who obtains an already authenticated browser session may not need to pass through the normal password and two-factor authentication flow again. Anthropic’s mitigation steps, as reported by BleepingComputer, include signing affected users out of Claude, revoking compromised sessions, removing saved payment methods, and refunding charges it identifies as unauthorized. The company also warned that signing a user out of Claude stops the stolen session but does not remove the malware from the user’s computer; if the machine remains infected, the next login session could be stolen in the same way. BleepingComputer says Anthropic identified multiple malware families in connection with the incidents. The Windows malware named in the report includes Vidar, LummaC2, StealC, RedLine, and Acreed. Anthropic also reportedly found Atomic Stealer, also known as AMOS, on a small number of Macs. The report includes one user-level example but does not establish a broad infection path. BleepingComputer says the Reddit user who shared the Anthropic email also said they had downloaded a pirated game, which may explain that person’s compromise. That anecdote should not be read as the cause for every affected Claude account. For affected users, Anthropic’s advice is operational rather than Claude-specific: remove the malware, change credentials, revoke other sessions, and treat the infected computer as the source of the problem. The company’s investigation is ongoing, according to the report, and the available summary does not disclose how many Claude users were affected, how much usage was consumed, or the total value of any unauthorized charges. Who benefits: Users who quickly revoke sessions, remove malware, and rotate credentials are best positioned to prevent repeat theft. Anthropic also reduces payment and support exposure by signing out affected users and removing saved payment methods. Who's exposed: Claude users with infected Windows PCs or Macs remain exposed if the malware is not removed before they log in again. Any other services with locally stored credentials or active browser sessions on the same machine may also be at risk, according to the malware behavior described in the report.