Anthropic accidentally exposed the source code of its Claude Code CLI after publishing npm package version 2.1.88 with a large JavaScript source map that pointed to unobfuscated TypeScript files hosted in company-controlled storage. Researcher Chaofan Shou identified the issue, which exposed roughly 1,900 to 2,000 files and more than 512,000 lines of code before the package was removed. Anthropic said the incident was caused by a manual release-packaging error rather than an external intrusion, and stated that no customer data or credentials were leaked. The code was quickly mirrored and forked on GitHub, making containment difficult, while Anthropic later acknowledged that automation gaps in its deployment process contributed to the exposure.
Analysis of the leaked code revealed internal architecture and unreleased capabilities including KAIROS background autonomy, persistent memory features, multi-agent orchestration, hidden feature flags, undocumented commands, and controls intended to resist model distillation or disclosure of internal names. Security researchers warned that exposing Claude Code’s permission logic, trust boundaries, prompts, and execution pathways could help attackers craft jailbreaks, prompt-injection lures, malicious repositories, and persistence techniques against the tool. Anthropic’s response also drew scrutiny after a DMCA notice led GitHub to disable thousands of legitimate forks before the company asked for narrower enforcement, and the leak’s impact was compounded by reports of typosquatted npm packages and a separate compromised axios dependency affecting some npm installs during the same period.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
After developer complaints, Anthropic asked GitHub to limit enforcement to the 96 fork URLs specifically listed in the notice and to restore other repositories disabled by network-wide processing. Anthropic representatives said the broader removals were unintentional and resulted from a communication mistake.
GitHub removed a network of about 8,100 similar forked repositories after a leak-related DMCA submission alleged the forks were infringing to the same extent as the parent repository. Many affected repositories reportedly did not contain leaked Claude Code material.
Anthropic disclosed that the incident stemmed from a manual deployment step that should have been better automated. The company said it implemented automation improvements to prevent a recurrence.
Anthropic pulled the exposed Claude Code npm package within hours of the leak being discovered. By that point, mirrors had already propagated the source code broadly online.
Anthropic said the Claude Code exposure was caused by a release packaging mistake due to human error rather than an external breach. The company also stated that no customer data or credentials were exposed.
Following the spread of the leaked repository, Anthropic sent DMCA takedown notices aimed at removing copies of the Claude Code source from GitHub and other locations. Reports indicate the legal effort struggled to contain already mirrored material.
Some reports said a separate npm supply-chain compromise involving Axios versions 1.14.1 and 0.30.4 may have impacted Claude Code npm installs during a narrow window on 2026-03-31 UTC. This compounded concerns around the package distribution path during the leak.
After the leak was identified, the exposed Claude Code source was archived, uploaded to GitHub, mirrored, and widely forked, making containment difficult. Multiple reports note that copies spread quickly before effective removal could occur.
On 2026-03-31, security researcher Chaofan Shou publicly identified and disclosed that the Claude Code npm package leaked source through a .map file. The disclosure drew rapid attention to the exposed archive and its contents.
On 2026-03-31, Anthropic's npm package version 2.1.88 for Claude Code was published with a large source map/debug artifact that exposed unobfuscated TypeScript source code from the product. Reports say the package enabled access to roughly 1,900 files and more than 512,000 lines of code hosted via Anthropic-controlled storage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
25 references tracked. Mallory keeps watching after this page renders.
infosecwriteups.com
Open sourcevulnu.com
Open sourcego.theregister.com
Open sourceosintteam.blog
Open sourcetheregister.com
Open sourcealex000kim.com
Open sourcetech.yahoo.com
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.