Signal

Malware is stealing Claude login sessions and draining paid usage — a cheap lesson for anyone budgeting AI tool spend

Anthropic has warned that infostealer malware — including Vidar, LummaC2, StealC, RedLine, and Atomic Stealer on Mac — is lifting active Claude session cookies from infected machines and using them to consume victims' paid usage, bypassing MFA entirely because the stolen session is already authenticated.