The attack on Claude accounts is widening: a second chain and a reinfection trick surface
The stolen-sessions case has a sequel: fake Claude Desktop installers hit 29 organizations in two days, and poisoned SKILL.md files re-download the malware even after cleanup.
The stolen Claude sessions case we reported two days ago turns out to be part of a larger campaign. According to a roundup by Cyber Security News, there are now two confirmed attack chains, and both target Claude accounts.
The first chain continues the story we knew: Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, plus Atomic Stealer on macOS, steal authenticated session cookies rather than passwords, which sidesteps two-factor authentication entirely. Attackers replay the stolen session and burn through the victim's paid usage; Anthropic caught the pattern when usage limits kept refilling and draining while account owners were inactive. The new and unsettling detail: commands hidden in poisoned SKILL.md configuration files can silently re-download the infostealer onto a cleaned machine, and if the tainted file is reintroduced, that can survive even a full OS reinstall.
The second chain ties an earlier incident into the campaign: on July 21-22, fake Claude Desktop installers spread through Bing ads used DLL sideloading to plant SectopRAT, a .NET remote access trojan. The report counts roughly 7,100 downloads before takedown, with at least 29 organizations compromised in two days.
On Anthropic's side the playbook is the one from our earlier story: compromised accounts are signed out, saved payment methods removed, fraudulent usage refunded. The company's warning still stands: those account-side fixes do NOT remove malware from an infected device. If your machine shows these signs, signing out is not enough; run a trusted scan and manually inspect any suspicious SKILL.md files.