Anthropic Warns Claude Users of Infostealer Malware Infections
Anthropic has detected infostealer malware infections among Claude users and is responding by forcing account logouts and removing stored payment information to prevent unauthorized access to compromised accounts. The company is taking these protective measures to limit potential misuse of affected user accounts while infections are remediated.
Check Point Research has analyzed JSCeal, a stealer malware distributed as compiled V8 bytecode and executed through a bundled Node.js runtime, which has been actively targeting cryptocurrency applications since March 2024 under various names including WEEVILPROXY and MeadowLocust. The research demonstrates static deobfuscation techniques for reversing JSCeal's compiled bytecode, providing visibility into the malware's obfuscation mechanisms and operational details.
Silver Fox threat actors are distributing the ValleyRAT backdoor disguised as QN Wallpaper, a legitimate Chinese desktop-wallpaper application, which users often add to antivirus exclusions due to its signed status. By running the malware under this trusted process, attackers can evade detection on systems where users have already whitelisted the application. Kaspersky identified this distribution method as part of the group's campaign to establish backdoor access while bypassing security controls.
Anthropic has begun locking Claude users out of their accounts after detecting compromised login sessions caused by infostealer malware infections on users' devices. The campaign leverages multiple infostealers including Vidar, Lumma, StealC, RedLine, and Acreed on Windows systems, as well as Atomic Stealer on a limited number of Macs, with these general-purpose malware typically arriving through unofficial downloads or malicious applications. Affected users received notification emails explaining the account lockouts as a protective measure against the credential theft campaign.
Boston Scientific engaged CrowdStrike and additional forensic partners to investigate a cyberattack that disrupted its global network operations. The medical device manufacturer continues recovery efforts following the incident.