PulseAugur
EN
LIVE 23:13:02

Malware hijacks Claude sessions, draining accounts; new AI agent supply-chain risks emerge

Malware targeting user machines has led to the hijacking of active Claude login sessions, allowing attackers to drain paid usage quotas. Anthropic responded by forcing users to log out, removing saved payment methods, and refunding unauthorized charges. A more sophisticated attack vector involves malicious `SKILL.md` files, which can reintroduce malware even after a system wipe, highlighting a new supply-chain threat for AI agent systems. This incident underscores that the compromise occurred on user devices, not Anthropic's servers, and that AI assistants can inadvertently facilitate malware delivery if their recommendations are not independently verified. AI

IMPACT Highlights new attack vectors for AI agents and the need for user-side security against session hijacking and supply-chain threats.

RANK_REASON The cluster describes a security incident affecting users of an AI product and highlights new attack vectors related to AI agent systems, rather than a core AI model release or research breakthrough.

Read on Mastodon — mastodon.social →

AI-generated summary · Google Gemini · from 10 sources. How we write summaries →

Malware hijacks Claude sessions, draining accounts; new AI agent supply-chain risks emerge

How we ranked this

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
The cluster describes a security incident affecting users of an AI product and highlights new attack vectors related to AI agent systems, rather than a core AI model release or research breakthrough.
Source corroboration
10 independent sources
Strong cross-source corroboration — multiple independent publishers covered this within the clustering window.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
1 days old
Coverage has settled into its steady-state source set.
Coverage growth since scoring
+2 source(s) since last score
New sources have picked up this story since our last re-score. Score will update on the next scoring pass.

Full methodology in our editorial standards.

COVERAGE [10]

  1. dev.to — Anthropic tag TIER_1 English(EN) · Faith & Fact - Marky Mark ·

    Malware Is Draining People's Claude Accounts Without Ever Logging In — So Anthropic Signed Everyone Out

    <p>Here's a fact: your password can be the length of a phone book and it wouldn't have mattered. Over the weekend, Anthropic started signing Claude users out of their own accounts — not because they did anything wrong, but because malware on their machines had already walked thro…

  2. dev.to — Anthropic tag TIER_1 English(EN) · Peremptory ·

    Claude Sessions Are Being Stolen by Common Infostealer Malware

    <p>Claude users are discovering their login sessions have been stolen and their paid usage quotas drained by people they've never heard of. Anthropic announced yesterday that attackers using common infostealer malware, Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and Atomi…

  3. Medium — Claude tag TIER_1 English(EN) · Cyber Chronicle ·

    Infostealers Are Now Hijacking AI Sessions: Why Your Claude Account Can Be Abused Without Your…

    <div class="medium-feed-item"><p class="medium-feed-image"><a href="https://meetcyber.net/infostealers-are-now-hijacking-ai-sessions-why-your-claude-account-can-be-abused-without-your-e3955700d7c5?source=rss------claude-5"><img src="https://cdn-images-1.medium.com/max/1536/1*Z1Zn…

  4. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    🤖 Anthropic warns infostealer malware has been hijacking active Claude login sessions on compromised PCs, letting attackers access accounts and drain users' usa

    🤖 Anthropic warns infostealer malware has been hijacking active Claude login sessions on compromised PCs, letting attackers access accounts and drain users' usage. Users advised to revoke sessions and scan infected machines. 🔗 https://www. bleepingcomputer.com/news/arti ficial-in…

  5. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    # Anthropic warns # infostealer # malware is hijacking # Claude sessions to drain usage https://www. bleepingcomputer.com/news/arti ficial-intelligence/anthropi

    # Anthropic warns # infostealer # malware is hijacking # Claude sessions to drain usage https://www. bleepingcomputer.com/news/arti ficial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/ # AI # cybersecurity

  6. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Bleeping Computer: Anthropic warns infostealer malware is hijacking Claude sessions to drain usage. “Anthropic is warning some Claude users that infostealer mal

    Bleeping Computer: Anthropic warns infostealer malware is hijacking Claude sessions to drain usage. “Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage…

  7. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    "Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and

    "Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage." https://www. bleepingcomputer.com/news/arti ficial-intelligence/anthropic-warns-infostealer-malwa…

  8. Mastodon — mastodon.social TIER_1 English(EN) · thedailyfathom ·

    AI · Anthropic warns hackers are hijacking Claude logins Malware is stealing people's active login sessions and using them to drain their paid Claude usage, Ant

    AI · Anthropic warns hackers are hijacking Claude logins Malware is stealing people's active login sessions and using them to drain their paid Claude usage, Anthropic says. Read the rest at: https:// thedailyfathom.com/ai/2026-08- 31/ # AI # Anthropic # Claude # TheDailyFathom

  9. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Malicious `SKILL.md` Files Are Becoming an AI Agent Supply-Chain Problem A reported Claude-related malware incident highlights a nasty attack chain: A user foll

    Malicious `SKILL.md` Files Are Becoming an AI Agent Supply-Chain Problem A reported Claude-related malware incident highlights a nasty attack chain: A user followed an AI-provided download link and was reportedly infected. After wiping the machine, they discovered a malicious `SK…

  10. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    Claude-Provided Malware Link Leads to Hack, Exposes New AI Agent Skill Supply-Chain Threat A Claude user reportedly suffered a malware infection after following

    Claude-Provided Malware Link Leads to Hack, Exposes New AI Agent Skill Supply-Chain Threat A Claude user reportedly suffered a malware infection after following an AI-provided download link, then discovered a poisoned SKILL.md capable of restoring malware and stealing credentials…