# Information-stealing malware developments

> Live situation record from CLSTR: https://clstr.news/situations/information-stealing-malware-developments
> Updated: 2026-09-03T04:30:01.000Z. Sources: 4. Developments: 3.

Security researchers have identified several information-stealing malware strains targeting different operating systems and user behaviors.

AmnesiaStealer, a Rust-based malware, targets macOS users through ‘ClickFix’ campaigns. It uses fake GitHub download pages to trick users into executing malicious terminal commands. The malware is capable of hijacking browser sessions by copying Chromium profiles and using a ‘stream_module’ to gain interactive remote control. It targets data including passwords, cryptocurrency wallets, Apple Notes, and Telegram sessions.

RevStealer targets Windows users by masquerading as fake desktop applications, such as ‘Claude Opus 5 Free Desktop,’ distributed via GitHub and game cheat websites. This malware is designed to evade detection by checking for sandbox environments and attempting to add itself to the Microsoft Defender exclusion list. It specifically targets credentials from over 50 cryptocurrency wallets and 12 password managers, while using Polygon smart contracts as a backup command-and-control channel.

Recent developments show that infostealer malware is being used to harvest active login sessions from Anthropic Claude users, allowing attackers to exhaust usage limits and make unauthorized charges. Identified malware families involved in these attacks include Vidar, Lumma, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer (AMOS) on macOS. Anthropic has responded by forcing session logouts, removing saved payment cards, and issuing refunds.

Additionally, a large-scale campaign has been uncovered involving 19 popular extensions for Google Chrome and Microsoft Edge. Attackers purchased legitimate applications or created functional utilities and then injected malicious code via updates to siphon passwords and cryptocurrency wallets. One specific extension, ‘Enable Right Click & Copy’, reportedly affected nearly 70,000 users. While removed from official stores, these extensions remain active on infected machines and require manual uninstallation.

## Timeline

### 2026-09-03: Cybersecurity threats target Anthropic Claude users and browser extensions

Cybersecurity alerts warn of infostealer malware targeting Anthropic Claude sessions and malicious browser extensions for Chrome and Edge designed to steal passwords and cryptocurrency.

2 sources. https://clstr.news/cluster/cybersecurity-threats-target-anthropic-claude-users-and-browser-extensions

### 2026-09-02: RevStealer malware targets crypto wallets via fake Claude Opus 5 apps

A new malware named RevStealer is targeting users via fake Claude Opus 5 desktop apps to steal cryptocurrency wallets, passwords, and sensitive browser data.

2 sources. https://clstr.news/cluster/revstealer-malware-targets-crypto-wallets-via-fake-claude-opus-5-apps

### 2026-08-16: AmnesiaStealer malware targets macOS users via browser hijacking

AmnesiaStealer, a new macOS malware, uses ClickFix attacks to hijack browser sessions and steal sensitive data, including passwords, cryptocurrency wallets, and keychain information.

5 sources. https://clstr.news/cluster/amnesiastealer-malware-targets-macos-users-via-browser-hijacking

---
Cite as: Information-stealing malware developments. CLSTR, https://clstr.news/situations/information-stealing-malware-developments
