logo

Anthropic Links Claude Session Theft to Infostealer Malware

ID: 53ab3a11-c984-5682-b2a3-e4fdec70d755

STIX ID: report--53ab3a11-c984-5682-b2a3-e4fdec70d755

Feed Name: SOCRadar Blog

Threat Score
65/100

Date Published: 2026-08-31

Date Updated: 2026-08-31

Author: ameer

...
...

Anthropic warned that infostealer malware on a user’s device stole active Claude browser sessions (cookies/credentials), enabling attackers to reuse authenticated sessions without completing sign-in or MFA; the incident reflects endpoint compromise rather than a Claude infrastructure breach. The report highlights risks to other exposed secrets (passwords, API keys, cloud credentials), recommends isolating/cleaning the device, revoking sessions, rotating credentials, and investigating broader exposure, and notes threat-intel and monitoring can help detect related leaks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.