Malware targeting user machines has led to the hijacking of active Claude login sessions, allowing attackers to drain paid usage quotas. Anthropic responded by forcing users to log out, removing saved payment methods, and refunding unauthorized charges. A more sophisticated attack vector involves malicious `SKILL.md` files, which can reintroduce malware even after a system wipe, highlighting a new supply-chain threat for AI agent systems. This incident underscores that the compromise occurred on user devices, not Anthropic's servers, and that AI assistants can inadvertently facilitate malware delivery if their recommendations are not independently verified. AI
IMPACT Highlights new attack vectors for AI agents and the need for user-side security against session hijacking and supply-chain threats.
RANK_REASON The cluster describes a security incident affecting users of an AI product and highlights new attack vectors related to AI agent systems, rather than a core AI model release or research breakthrough.
Read on Mastodon — mastodon.social →
- AI agents
- Anthropic
- Claude
- Claude Code
- Google.Cloud
- SKILL.md
- Infostealers
- Atomic Stealer
- infostealer malware
- RedLine
- SectopRAT
- StealC
- Vidar
AI-generated summary · Google Gemini · from 10 sources. How we write summaries →