Anthropic disclosed that five infostealer strains, Vidar, LummaC2, StealC, RedLine, and Acreed, are stealing active Claude sessions directly off infected machines. Not phishing, not a fake login page, the malware just needs to already be on your computer from something unrelated. If you or your team use Claude, ChatGPT, or similar tools on personal or lightly managed machines, this is worth 10 minutes today: run an anti-malware scan, check your active sessions in Claude and sign out of anything unfamiliar, and turn on two-factor if you haven't. Full breakdown: neonaliens.com/intel/claude-infostealer-malware-founders.html Has anyone here actually run a malware scan on their main work machine recently, or is it one of those things everyone assumes is fine until it isn't?