Anthropic disclosed this week that infostealer malware, five specific strains named Vidar, LummaC2, StealC, RedLine, and Acreed, has been siphoning active Claude login sessions directly from infected users’ own computers and using them without permission, in some cases consuming the victim’s usage limits. Anthropic is proactively signing out affected accounts, wiping saved payment methods, and issuing refunds for unauthorized charges. This is different from the security stories we have covered all month involving sandbox escapes and supply chain compromises inside AI infrastructure itself. This threat lives on individual users’ own machines, and it is something you and your team can actually check for right now.

How This Actually Works

Infostealer malware is not new, and it is not specific to AI tools. It is a category of malicious software designed to sit quietly on an infected computer and harvest saved credentials, browser cookies, and active session tokens, then send that information back to whoever deployed it. What makes this disclosure relevant is that Claude accounts are now a confirmed target. If your computer is infected with one of these strains, your active Claude session can be lifted and used by someone else without you ever entering a password anywhere or clicking a suspicious link related to Claude at all. The malware does not need to trick you into giving up your login, it just needs to already be on your machine, picked up from an entirely unrelated infection vector, a fake software crack, a malicious browser extension, a compromised download.

Anthropic’s response, automatically signing out affected sessions and refunding unauthorized usage, is a reasonable and responsible reaction to a threat that originated outside their own systems. But it also means the fix on Anthropic’s end does not address the actual problem, since the malware is still on the infected machine, capable of stealing the next set of credentials the moment a new session starts.

Why This Matters More for a Small Team Than You Might Assume

Larger companies typically run endpoint security software, monitored IT policies, and centralized device management that would likely catch this kind of infection before it becomes a real problem. Small businesses and solo founders, along with contractors and freelancers who may have access to shared tools, often do not have that layer of protection. If you or anyone on your team uses Claude, ChatGPT, or similar AI tools on a personal or lightly managed computer, you are in the exact category of user this kind of malware is built to target effectively.

The consequence is not limited to Anthropic refunding unauthorized token usage. If your Claude account has access to sensitive work, client information, draft content, business strategy discussions, that access goes wherever your stolen session goes. This is a genuine business risk, not just a billing annoyance.

What to Actually Check Right Now

Run a reputable anti-malware scan on any computer you or your team uses to access Claude or other AI tools, particularly personal machines that are not centrally managed. Check your Claude account’s active sessions and login history if that feature is available, and sign out of any sessions you do not recognize. If you have not changed your Claude password recently, this is a reasonable moment to do so, along with enabling two-factor authentication if you have not already.

More broadly, this is a useful prompt to ask a question most founders skip: does anyone on your team download software from unofficial sources, use pirated tools, or click through browser extensions without checking their legitimacy. Infostealer malware overwhelmingly spreads through exactly those channels. Basic device hygiene, keeping software updated, avoiding unofficial downloads, running real endpoint protection, is not exciting advice, but it is the actual answer to a threat like this one.

The Broader Pattern Worth Noticing

This is the fourth distinct category of AI-related security incident we have covered in the past month: a model escaping its own sandbox, a supply chain compromise through a poisoned dependency, an intentionally built offensive AI access program, and now credential theft targeting individual users through conventional malware. Each one has a different root cause and a different fix, which is itself the point. There is no single security practice that protects against all of these. Layered, boring, unglamorous security hygiene, on your infrastructure, your dependencies, and your own devices, is what actually closes these gaps, not any single tool or setting.


If you want to think through where else your AI tools might have more access than you have accounted for, this is worth revisiting: An OpenAI Model Escaped Its Own Sandbox. Here’s Why Founders Should Care.

Want results like this for your brand?

We work with a small number of founders at a time. See if you qualify.

See If We’re a Fit