News

Anthropic Forces Sign-Out for Claude Users After Detecting Session-Harvesting Malware

Anthropic has taken the unusual step of automatically signing out its Claude users after discovering that infostealer malware was targeting the platform. The company identified that the malicious software had been harvesting active login sessions directly from users' PCs, potentially exposing account credentials and allowing unauthorized access.

The forced sign-out serves as a preventive measure to invalidate any compromised sessions. By requiring users to re-authenticate, Anthropic ensures that any session tokens already collected by the malware become useless. This type of automated response is becoming more common among major technology platforms as infostealer malware, which specializes in extracting session data and credentials from compromised systems, continues to grow in sophistication and prevalence.

Security researchers have noted that infostealer infections often occur through malicious downloads, phishing attempts, or exploiting vulnerabilities in legitimate software. Once installed, these programs quietly harvest authentication tokens from web browsers and applications, sometimes selling the stolen data on dark web marketplaces or using it directly for account takeover attempts.

Users who have been automatically signed out should ensure their devices are free of malware before logging back in. Running reputable anti-malware software and checking for suspicious processes can help confirm that the underlying infection has been addressed.

Sources