Anthropic has alerted users about infostealer malware campaigns specifically designed to hijack Claude AI sessions by stealing browser cookies and authentication tokens. Once these tokens are exfiltrated, attackers can bypass multi-factor authentication (MFA) to access user accounts, view sensitive chat history, and deplete account usage limits or credits.
This incident underscores the evolving threat landscape where cybercriminals are increasingly targeting generative AI platforms to exploit valuable compute resources and personal data. Organizations and individuals are advised to maintain updated antivirus software and clear active sessions if compromise is suspected.
Top comments (0)