{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0416",
  "aliases": [],
  "modified": "2026-09-20T00:00:00Z",
  "summary": "Infostealers hijack Claude sessions and drain usage",
  "details": "## What\n\nThe cited account-hijack notices describe common infostealer malware replaying Claude browser sessions. Users saw usage allowances drained and auto-reload charges; providers signed users out, removed payment methods, and refunded charges. The sources do not name a hard-coded Claude Code OAuth path.\n\n## Which configuration is exposed\n\nThe record targets a workstation that runs Claude tooling and also holds browser sessions or other session material. It is a target-set warning rather than an infection finding. A local harness presence cannot show whether malware arrived, what it read, or whether a session was replayed.\n\n## How ACVE detects it\n\nACVE matches the presence of Claude Code or Claude Desktop in the lock. It does not inspect browser profiles, credentials, or cookies. A match should trigger endpoint investigation and session revocation, not a claim that the local account was abused.\n\n## Fix\n\nSign out all sessions, remove payment methods while investigating, rotate tokens, and scan the endpoint for infostealer persistence. Use short-lived credentials and hardware-backed or isolated authentication where available.\n\n## Grounding needed\n\nThe cited notices should be checked for the incident dates and response actions. The victim count is undisclosed, and the record does not convert a harness target set into an infection count.\n\nThis record is limited to the condition named in the public source: Infostealers hijack Claude sessions and drain usage. A match is a review signal for that condition, not a claim that every installation, package, model, or host was compromised. Operators should preserve the resolved evidence and investigate adjacent credentials, network exposure, and execution history before closing the finding. The result should be retained with the lock snapshot used for the match so later review can distinguish configuration drift from a changed public record.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "claude-code"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "code",
      "vulnClasses": [
        "credential-theft"
      ],
      "cwe": [
        "CWE-522"
      ],
      "exploitation": {
        "status": "exploited-itw",
        "checkedAt": "2026-09-20T00:00:00Z",
        "sources": [
          {
            "url": "https://www.malwarebytes.com/blog/news/2026/09/infostealers-are-hijacking-claude-accounts-at-users-expense",
            "type": "dfir"
          },
          {
            "url": "https://www.helpnetsecurity.com/2026/08/31/claude-accounts-compromised-through-infostealer/",
            "type": "news"
          }
        ],
        "kev": {
          "listed": false
        },
        "first_seen": "2026-08-31",
        "last_seen": "2026-09-01",
        "victims": {
          "range": "count undisclosed",
          "sectors": [
            "software"
          ],
          "evidence": "Anthropic-related notices describe drained usage, auto-reload charges, sign-outs, refunds, and payment removal."
        },
        "attribution": "unattributed"
      },
      "cveBoundary": "user-configured",
      "matcher": {
        "field": "harness.id",
        "op": "in",
        "value": [
          "claude-code",
          "claude-desktop"
        ]
      },
      "fix": {
        "summary": "Sign out Claude sessions and remove infostealer persistence.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "harness.id",
            "why": "Invalidate sessions on affected endpoints."
          },
          {
            "type": "remove",
            "target": "browser session material",
            "why": "Remove replayable cookies after sign-out."
          }
        ]
      },
      "noCveReason": "No CVE assigned; this record describes a configuration or supply-chain condition.",
      "grounding": {
        "itw": {
          "checkedAt": "2026-09-20T16:26:30Z",
          "sources": [
            {
              "url": "https://www.malwarebytes.com/blog/news/2026/09/infostealers-are-hijacking-claude-accounts-at-users-expense",
              "status": 200,
              "contentType": "text/html; charset=UTF-8",
              "sha256": "sha256:ffad35c43ef8cdce2c68781972ffac0f4e2dfcce59adf00a74ac30027bcd5771",
              "type": "dfir"
            },
            {
              "url": "https://www.helpnetsecurity.com/2026/08/31/claude-accounts-compromised-through-infostealer/",
              "status": 200,
              "contentType": "text/html; charset=UTF-8",
              "sha256": "sha256:db3c1ff7db15a7a177f538ae9c7bebc9203529e1620480907d4d06605eda72bd",
              "type": "news"
            }
          ],
          "kev": {
            "listed": false
          }
        }
      }
    }
  }
}
