The Claude AI platform, developed by Anthropic, has recently become a significant target for cybercriminals, with confirmed reports of two distinct attack chains aimed at compromising user accounts. These attacks involve the theft of login credentials, unauthorized usage of paid services, and the reinfection of devices even after cleanup efforts.
The Extent of the Breach
Anthropic is actively responding to this threat by signing out affected accounts, removing stored payment methods, and issuing refunds for unauthorized transactions. The company is working diligently to mitigate the damage caused by these breaches.
According to Anthropic’s advisory, several infostealer malware families, including Vidar, Lumma, StealC, RedLine, and Acreed on Windows, and Atomic Stealer on macOS, are involved. These malware variants are designed to quietly extract saved passwords, browser cookies, and locally stored credentials from infected systems.
Mechanics of the Attack
The infostealer malware operates by capturing already-authenticated session cookies, effectively bypassing two-factor authentication and single sign-on defenses. This allows attackers to replay the victim’s session, using their paid resources without needing direct login access. Anthropic identified this pattern after observing account usage limits being reset and depleted while account holders remained inactive.
In a related development, security firm Huntress has tracked a threat named FakeAgent, which exploits Claude’s infrastructure. Between July 21 and July 22, 2026, users searching for the “Claude desktop app” on Bing encountered sponsored ads leading to a malicious Claude Artifact hosted on the legitimate claude.ai domain. This malicious installer, disguised as ClaudeDesktop.exe, executed DLL sideloading to deploy SectopRAT, a remote access trojan that collects browser credentials and other sensitive data.
Ongoing Threats and Recommendations
Another emerging threat involves poisoned SKILL.md files, configuration files used by Claude’s agent skills. Attackers insert malicious instructions disguised as ordinary notes, enabling the persistent re-download of infostealer malware even after a full system reinstall if the tainted file is reintroduced.
Anthropic has taken steps to address these issues by signing out compromised sessions and removing stored payment methods. However, these measures do not eliminate malware from infected devices. Security experts recommend conducting thorough malware scans before logging back into Claude, resetting associated email passwords with two-factor authentication, and updating browser-stored credentials.
Organizations using Claude should also sandbox AI environments and audit SKILL.md or similar files for hidden commands. This incident highlights the importance of treating AI-suggested links or commands with the same caution as suspicious email attachments to prevent future breaches.
For comprehensive protection, integrating threat intelligence and auditing practices is crucial for organizations deploying AI technologies at scale.
