< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Cybersecurity threats target Anthropic Claude users and browser extensions

Cybersecurity threats targeting web users have been identified involving both AI service accounts and browser extensions.

Anthropic has taken steps to protect Claude users after discovering that infostealer malware on users' personal computers was harvesting active login sessions. This allowed attackers to exhaust usage limits and make unauthorized charges. Anthropic responded by forcing session logouts, removing saved payment cards, and issuing refunds. Identified malware families include Vidar, Lumma, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer (AMOS) on macOS.

Separately, a large-scale campaign has been uncovered involving 19 popular extensions for Google Chrome and Microsoft Edge. According to experts at Socket, these extensions were used to siphon passwords and cryptocurrency wallets. The attackers utilized a method of purchasing legitimate applications or creating functional utilities and then injecting malicious code via updates. One specific extension, ‘Enable Right Click & Copy’, reportedly affected nearly 70,000 users. Although the extensions have been removed from official stores, they remain active on infected machines and require manual uninstallation.

Entities

Anthropic · Claude · Google Chrome · Microsoft Edge · Socket