ACVEAgent configuration vulnerability registry

ACVE-2026-0416

Infostealers hijack Claude sessions and drain usage

Part of campaign: Agent credential stealers

In the wild

exploited-itw · 2026-08-31 – 2026-09-01 · dfir, news

Description

What

The cited account-hijack notices describe common infostealer malware replaying Claude browser sessions. Users saw usage allowances drained and auto-reload charges; providers signed users out, removed payment methods, and refunded charges. The sources do not name a hard-coded Claude Code OAuth path.

Which configuration is exposed

The record targets a workstation that runs Claude tooling and also holds browser sessions or other session material. It is a target-set warning rather than an infection finding. A local harness presence cannot show whether malware arrived, what it read, or whether a session was replayed.

How ACVE detects it

ACVE matches the presence of Claude Code or Claude Desktop in the lock. It does not inspect browser profiles, credentials, or cookies. A match should trigger endpoint investigation and session revocation, not a claim that the local account was abused.

Fix

Sign out all sessions, remove payment methods while investigating, rotate tokens, and scan the endpoint for infostealer persistence. Use short-lived credentials and hardware-backed or isolated authentication where available.

Grounding needed

The cited notices should be checked for the incident dates and response actions. The victim count is undisclosed, and the record does not convert a harness target set into an infection count.

This record is limited to the condition named in the public source: Infostealers hijack Claude sessions and drain usage. A match is a review signal for that condition, not a claim that every installation, package, model, or host was compromised. Operators should preserve the resolved evidence and investigate adjacent credentials, network exposure, and execution history before closing the finding. The result should be retained with the lock snapshot used for the match so later review can distinguish configuration drift from a changed public record.

Configuration

harness.id in ["claude-code","claude-desktop"]

Fix

Sign out Claude sessions and remove infostealer persistence.

  • Reconfigure harness.id. Invalidate sessions on affected endpoints.
  • Remove browser session material. Remove replayable cookies after sign-out.

Validation

No validation entries recorded.

Grounding

No grounding checks recorded.

References

No references recorded.

Report a problemValidate this advisoryDiscussJSONEdit on GitHub