Anthropic has issued a warning regarding infostealer malware targeting session tokens to hijack Claude AI accounts. Attackers are leveraging malware variants like Lumma Stealer and Meduza to exfiltrate browser cookies, allowing them to bypass multi-factor authentication and access user sessions directly.
Once compromised, these sessions are used to drain API credits or usage limits, potentially exposing sensitive conversations. Users are advised to monitor for suspicious activity and clear browser cookies if they suspect a compromise.
Top comments (0)