TechCrunch (Sep 8, 2026) reported that attackers are using infostealer malware to steal Claude subscribers' authentication sessions β grabbing browser cookies and active session keys rather than passwords β and using those keys to mint unauthorized Claude Code OAuth tokens that drain paid accounts before owners notice. A victim's GitHub report prompted an Anthropic investigation; warning emails (first reported by BleepingComputer Aug 30, circulating as unauthenticated copies) describe infostealers as the vector, with Anthropic revoking sessions, removing payment methods, and refunding victims β several secondary outlets characterize this as Anthropic confirmation, but no authenticated first-party statement is on record. A later Oct 7 self-published Warden telemetry post claims stealer logs are exfiltrating raw .claude.json API keys and OAuth tokens directly from developer machines, an independent but unverified observation consistent with the reported mechanism.
Converges: Warden telemetry showing stealer logs exfiltrating raw .claude.json primaryApiKey values and OAuth tokens moves the plaintext-credential complaint from storage-risk claim to observed in-the-wild theft, independently confirming the premise SiloOS/runtime-containment is built on β ambient host credentials on agent workstations are live attack surface β and it lands on his daily driver (Claude Code) and his documented shared-authenticated-browser-session practice. High rather than medium because it creates an action item (audit and rotate his own stored Claude credentials), strengthens the argument for his Nango-style brokered-credential pattern over plaintext-on-disk, and hands him a dated receipt for the 'scoped, minted, revocable keys instead of ambient secrets' thesis; the telemetry source is self-published, so the receipt is provisionally priced.
ip:framework.siloosdev:project.silo-osdev:technology.claude-codedev:concept.shared-authenticated-browser-sessionip:concept.runtime-containmentradar:claude-code-plaintext-oauth-tokensradar:concept.claude-coderadar:concept.credential-securityradar:concept.credential-isolationradar:concept.credential-theftradar:claude-artifact-macos-infostealer
queries asked of Scott's wikis
- Claude Code credential storage and plaintext API key exposure
- credential isolation practices for coding agent harnesses
- shared browser session risk in authenticated agent workflows
- OAuth token minting and delegated access in dev tooling
- infostealer threat model for developer workstations
- agent runtime secrets management in local environments
now 0 pts/hpeak 30 pts/hcomments 0/hpeers p37momentum: steady3 platformsage 1034h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion
2026-10-10T22:26:06Z
ClickFix malvertising campaign (hn.story.50037299) adds a third observed vector β phishing via malicious ads β to the infostealer and direct .claude.json exfiltration evidence, confirming an active multi-vector credential-theft campaign targeting Claude users. The core assessment holds: plaintext API keys and OAuth tokens on developer machines are live attack surface; prevalence, a second confirmed victim, and authentication of the Anthropic email or Warden telemetry remain open.
2026-10-10T21:38:13Z
evidence attached: hn.story.50037299 β ClickFix attacks targeting Claude users corroborate ongoing credential-theft campaign
2026-10-07T14:43:17Z
grounded: converges/high β Converges: Warden telemetry showing stealer logs exfiltrating raw .claude.json primaryApiKey values and OAuth tokens moves the plaintext-credential complaint fr
2026-10-07T14:34:21Z
The infostealer vector, previously resting solely on unauthenticated echo testimony of Anthropic's warning email, now has an independent telemetry observation β Warden stealer logs exfiltrating .claude.json primaryApiKey values and OAuth tokens β giving the case two genuinely independent lines on mechanism (incident reporting + in-the-wild stealer behavior), which is why it passes corroborated despite near-zero engagement. The meaning shifts from 'one reported incident plus a string of failed usage-anomaly candidates' to 'credential theft via infostealers observed in the wild'; prevalence, a second confirmed victim, and authentication of either the email or the telemetry remain open, and the telemetry source itself is self-published and unverified.
2026-10-07T14:27:38Z
evidence attached: reddit.post.1wzxqlq β Independent corroboration: infostealer telemetry shows .claude.json API keys and OAuth tokens being exfiltrated, matching the reported Claude token theft.
2026-10-06T22:50:54Z
The Oct 6 '98% Other' post is a closer-matching theft signature than prior quota complaints β unattributable category usage with features disabled and $0 spent β but it is single, unconfirmed, near-zero engagement, and a metering/dashboard anomaly explains it as easily as theft. The case's meaning is unchanged: still a low-heat standing watch with no confirmed second victim; the real test now is whether a cluster of 'unattributable category' reports appears.
2026-10-06T20:42:17Z
evidence attached: reddit.post.1wz8x7r β Unattributed usage (98% 'Other') with all features disabled and $0 spent is a possible footprint of unauthorized token use β single, unconfirmed instance.
2026-09-30T01:39:02Z
The Max-5x overnight-reset post fails as theft corroboration: weekly usage falling 90%β0% with the banked Opus 5.5 reset consumed and reset day unchanged matches an auto-applied gift reset rather than a thief burning quota, and no other user reports the same. The case settles back to a low-heat standing watch on Claude credential abuse, anchored by the unauthenticated Anthropic email echo and the still-unverified Claudecookie tool.
2026-09-30T00:38:31Z
evidence attached: reddit.post.1wtpq7n β Possible independent corroboration: Max-5x account shows usage the owner denies performing overnight, consistent with token theft β though an undocumented auto-applied gifted reset is the rival explanation worth carrying.
2026-09-19T23:21:50Z
The Claudecookie submission advertises functionality matching the reported session-to-Claude-Code credential path, but the supplied evidence contains only a titleβnot code, a working demonstration, or evidence of malicious use. It adds a concrete verification lead, not independent corroboration of active theft or a demonstrated change in exposure.
2026-09-19T23:21:34Z
evidence attached: hn.story.49770860 β A concrete tool for converting and minting Claude Code credentials materially corroborates the active Claude credential-abuse risk.
2026-09-11T19:35:44Z
The additional HN thread recirculates the same report; its quoted complaint highlights difficulty attributing account usage but supplies neither independent corroboration nor a verified change in detection capabilities. The case remains a concrete credential-hygiene concern, not evidence of a broader Claude Code vulnerability or expanding compromise.
2026-09-11T19:22:13Z
evidence attached: hn.story.49662941 β shared external link with case evidence
2026-09-10T19:01:51Z
The refreshed comments offer ordinary workload explanations for rapid usage exhaustion, including one user's reported improvement after limiting subagents; they further weaken this anecdote as corroboration of theft without disproving the original reported abuse. No new unauthorized access, affected scope, or remediation requirement is established.
2026-09-10T13:32:19Z
The new usage-exhaustion anecdote does not independently corroborate theft: it identifies neither unauthorized activity nor a connection to the reported abuse. The original incident remains relevant to credential hygiene, but there is no new evidence of broader exposure, a Claude Code vulnerability, or changed remediation needs.
2026-09-10T13:23:27Z
evidence attached: reddit.post.1wcizto β A separate user reports unusually rapid token exhaustion, providing weak independent corroboration of possible unauthorized Claude subscription use.
2026-09-10T06:33:15Z
The evidence supports reported unauthorized subscriber-account use rather than merely potential token exposure, but does not independently establish the theft mechanism, scale, or a Claude Code vulnerability. This look adds no substantive evidence beyond the abuse report already routed for attention; the reconstructed warning email remains testimony, not authenticated first-party confirmation.
2026-09-10T06:29:27Z
grounded: converges/medium β The reported session-key-to-OAuth-token abuse gives Scott a concrete reason to review credential exposure and delegated access in his documented Claude Code and
2026-09-10T06:27:11Z
origin walked (codex/luna, conf 0.93): anchor hn.story.49639094 -> echo.x.28eef47b05 by Anthropic
2026-09-10T06:25:58Z
case created β The report identifies a concrete subscriber-token theft episode not represented by existing Anthropic incident cases, but does not establish its mechanism, scale, or resulting control changes.