Hackers Hijack Claude Accounts by Stealing Login Sessions with Infostealer Malware
Leave a Comment / Cybersecurity, Data Protection, Enterprise Technology, Industry News / By cxojunction
Anthropic‘s Claude AI platform has become an active target for cybercriminals, with attacks stealing credentials, hijacking paid usage, and maintaining access even after cleanup.

The attacks have prompted Anthropic to sign out compromised accounts, remove saved payment methods, and issue refunds as it works to contain the damage. According to the company’s advisory, infostealers including Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows, along with Atomic Stealer on macOS, have been copying saved passwords, browser cookies, and locally stored credentials. By stealing already-authenticated session cookies rather than passwords, attackers can bypass two-factor authentication and single sign-on, replay Claude sessions, and consume paid usage without logging in themselves.
A separate threat tracked by Huntress as FakeAgent also exploited Claude’s infrastructure. Between July 21 and July 22, 2026, victims searching Bing for the “Claude desktop app” were shown sponsored ads leading to a malicious Claude Artifact hosted on the legitimate claude.ai domain. The fake installer, disguised as ClaudeDesktop.exe, used DLL sideloading to deploy SectopRAT, a .NET remote access trojan capable of stealing browser credentials, credit card data, cookies, and files. Huntress confirmed at least 29 organizations were compromised in two days, with the malicious page recording roughly 7,100 downloads before Anthropic removed it.
Another emerging technique involves poisoned SKILL.md files used by Claude’s agent skills. Attackers hide malicious instructions within these files, allowing infostealers to be re-downloaded and credentials harvested when the files are loaded. One Web3 founder also reported nearly losing control of crypto wallets after a Claude chat suggested a terminal command that executed instantly and downloaded the payload. Security researchers recommend full malware scans, password resets, updated browser credentials, and caution around AI-suggested links and terminal commands.
For organizations, these incidents reinforce the need for stronger controls around AI platforms and agent environments. Sandboxing AI agents and auditing SKILL.md and similar configuration files can help reduce credential theft, unauthorized access, financial losses, and reinfection, while giving security teams greater visibility and control over enterprise AI deployments.
CXO Junction remains dedicated to providing you with exclusive insights into transformative leadership journeys. Stay tuned for more updates as we continue to bring industry news to you.
Source: Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts | The CyberSecurity News | https://cybersecuritynews.com/hackers-steal-claude-login-sessions/
