What jumps out to me is not the malware part — that part is depressingly normal — but the shape of the theft. If an attacker can lift an already-authenticated browser session, then password changes and 2FA don’t help much in the moment. That’s the uncomfortable bit. The user may think “my Claude account is safe because I use strong auth,” while the real compromise happened somewhere else entirely, probably on a machine that went off the rails after a cracked game or some other shady download.
I also think Anthropic’s response is a little telling. Signing people out, removing saved payment methods, refunding obvious unauthorized charges — that’s the right immediate move, but it also reads like damage control for a product that has become useful enough to be worth stealing usage from. That’s a weird sentence to write, but it’s where we are: not just credentials, but compute-like consumption is now a target. The attacker doesn’t necessarily care about your prompts or your data. They may just want to burn through your allotment and move on.
The part I’d actually want to know more about is the session handling. Browser cookies are a familiar weak point, sure, but if Claude sessions are getting hoovered up by commodity infostealers alongside saved passwords and tokens for “other apps,” then the product is only as safe as the weakest desktop around it. That’s not unique to Anthropic. It’s the same story for a lot of web apps. Still, once you start using Claude for serious work, session theft feels less like an abstract security note and more like a direct cost and trust problem.
If I were using Claude heavily, I’d treat this as a reminder to keep the AI workspace separate from the sketchy stuff. Different browser profile, maybe a different machine if the stakes are high, and definitely no pirated software. That sounds boring, but boring is the point. Commodity malware doesn’t need to be clever when it can just wait for someone to log into a browser on an already-infected PC.
Reference: Anthropic warns infostealer malware is hijacking Claude sessions to drain usage