415.tech
AI & tech, from the frontlines of Silicon Valley

Infostealers hijacked Claude session cookies, and Anthropic force-signed users out

Anthropic signed affected Claude users out, stripped saved payment methods, and refunded unauthorized charges after Vidar, LummaC2, StealC, RedLine, Acreed on Windows and Atomic Stealer on Macs harvested live session cookies from users' own machines. The compromise was local, not in Claude, and cookie replay walks past both passwords and 2FA — so session tokens are now the credential worth protecting, and signing out one service leaves every other active session on an infected machine still replayable.

Source: helpnetsecurity.com

Post on XEmail