415.tech
AI & tech, from the frontlines of Silicon Valley
Anthropic signs Claude users out after infostealers hijack session cookies

Anthropic signs Claude users out after infostealers hijack session cookies

Anthropic force-signed-out Claude accounts, stripped saved payment methods, and refunded unauthorized charges after six infostealer families — Vidar, Lumma, StealC, RedLine, Acreed on Windows, plus Atomic Stealer on a few Macs — copied session cookies off user machines. Because attackers replayed valid cookies instead of passwords, two-factor authentication stopped nothing, and the fix order matters: remove the malware first, or a fresh login hands the attacker a new session. Anthropic says the malware arrived through unofficial downloads and has no connection to Claude itself; one victim traced the infection to a pirated game.

Source: helpnetsecurity.com

Post on XEmail

2FA protects the login, but once the user has logged in, the site issues their browser a session cookie that keeps them signed in so they don't have to re-authenticate on every click. Infostealers copy that cookie and an attacker who "replays" it is treated as an already-logged-i

Anthropic

Why this matters

  • → Session hijacking bypasses 2FA — attackers replay stolen cookies as logged-in users.
  • → Malware cleanup order matters: remove infection first, or new logins hand attacker fresh sessions.
  • → Session theft is becoming the new credential-theft vector, shifting attack surface.
Session theft sidesteps 2FA