Skip to main content
Mallory
Back to intelligence
leaked-secret-api-keybreach-disclosure-notificationai-platform-securitypackage-repository-poisoning

Anthropic Claude Code CLI Source Exposed Through npm Source Map

Updated 28d agoFirst seen Mar 31, 202629 sources

Anthropic's proprietary Claude Code CLI source code was exposed after npm package version 2.1.88 reportedly shipped with a misconfigured source map that pointed to unobfuscated TypeScript files hosted on Anthropic-controlled infrastructure. Researcher Chaofan Shou publicly disclosed the issue, and the exposed archive was said to contain the full src/ directory—nearly 1,900 files and more than 512,000 lines of code—covering core engine logic, tools, commands, internal feature flags, and multi-agent coordination components.

The leaked material was quickly archived, posted to a public GitHub repository, and widely forked, enabling outside analysis of the CLI's internal memory architecture, validation mechanisms, API client logic, OAuth 2.0 authentication flows, and permission enforcement. Anthropic said the exposure resulted from a human packaging error rather than a breach and stated that no sensitive customer data or credentials were leaked, while the incident still raised intellectual property and security concerns because it revealed detailed implementation and architectural information about the product.

Share:
Anthropic Claude Code CLI Source Exposed Through npm Source Map
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

13 events from the most recent confirmed update back to the earliest known activity.

13 EVENTS
Apr 7, 20262mo ago

Anthropic reportedly withholds Mythos Preview and launches Project Glasswing

According to the new reference, Anthropic decided on 2026-04-07 not to publicly release Claude Mythos Preview after internal testing revealed unexpectedly strong offensive cyber capabilities. The article says Anthropic instead granted access to a private 'Project Glasswing' coalition of 12 organizations, backed by $100 million in usage credits.

Why game theory failed to predict the two biggest AI events of 2026 - and my framework didn’t | by Berend Watchus | Apr, 2026 | OSINT Team
Apr 3, 20262mo ago

Malicious GitHub repos use Claude Code leak to spread malware

After the March 31 Claude Code source exposure, Zscaler identified malicious GitHub repositories repackaging the leaked material and offering a ZIP archive with a Rust-based dropper. The payloads included Vidar v18.7 and GhostSocks, and one repository reportedly ranked highly in Google search results for "leaked Claude Code," increasing developer compromise risk.

Claude Code source leak exploited to spread malware - Help Net Security

Critical Claude Code vulnerability is publicly reported after source leak

Within days of the public exposure of Claude Code source, a critical vulnerability in Claude Code was reportedly publicly disclosed. The report framed this as evidence that the leaked code enabled attackers and researchers to systematically audit the agentic tool for exploitable flaws.

Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads | Trend Micro (US)
Apr 2, 20262mo ago

Public data store exposes Anthropic Mythos and Capybara model details

Anthropic reportedly had an unsecured public data store that exposed development information about its upcoming Mythos and Capybara AI models. The exposed material included internal characterizations of Capybara as more powerful than Opus and warnings that its cyber capabilities could outpace defenders if misused.

Anthropic's rough week: leaked models, exposed source code, and a botched GitHub takedown - The New Stack

Anthropic asks GitHub to restore legitimate forks hit by broad DMCA action

After a leak-focused DMCA notice triggered GitHub to disable about 8,100 forked repositories, including many legitimate forks of Anthropic's public repository that did not contain leaked code, Anthropic said the broad removals were unintentional. The company asked GitHub to limit enforcement to the 96 specifically identified fork URLs and restore the other affected repositories.

Anthropic says its leak-focused DMCA effort unintentionally hit legit GitHub forks - Ars Technica
Apr 1, 20262mo ago

Anthropic recommends native installer after npm leak and Axios supply-chain scare

After removing the exposed Claude Code npm package, Anthropic reportedly advised users to prefer its native installer over npm. The guidance came amid concern that a separate compromise of Axios npm versions 1.14.1 and 0.30.4 may have affected some Claude Code npm installs during a narrow March 31 UTC window.

Inside Claude Code's leaked source: swarms, daemons, and 44 features Anthropic kept behind flags - The New Stack

Typosquatted npm packages appear after Claude Code leak

Following the public exposure of Claude Code source, typosquatted npm packages were published that mimicked related package names, creating potential dependency confusion and follow-on supply-chain attack risk. The activity was reported as a secondary escalation after the original packaging error.

Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms

Anthropic says it automated deployment steps after Claude Code leak

Anthropic's Boris Cherny said the Claude Code source exposure was caused by a manual deployment step that should have been automated. He added that the company has since implemented automation improvements to help prevent a similar packaging mistake from happening again.

‘There was a manual deploy step that should have been better automated’: Claude Code creator confirms cause of massive source code leak | IT Pro
Mar 31, 20262mo ago

Anthropic says leak was a packaging error, not a breach

Anthropic stated that the exposure resulted from a human packaging mistake rather than a security breach. The company also said no sensitive customer data or credentials were exposed.

Anthropic reportedly issues DMCA takedown over mirrored Claude Code leak

After the exposed Claude Code source was mirrored on GitHub, Anthropic reportedly sent a DMCA takedown request seeking removal of the leaked material. This represented a follow-on response to the accidental npm source-map exposure and subsequent public archiving of the code.

������ ���� �������������� Claude Code ��-�� �������� � NPM-������ map-�����

Leaked Claude Code source is mirrored and widely analyzed

After the disclosure, the exposed Claude Code source was archived, uploaded to a public GitHub repository, and widely forked. Developers and researchers began examining the leaked codebase, including its internal memory architecture and validation mechanisms.

Researcher publicly discloses Claude Code source exposure

On March 31, 2026, researcher Chaofan Shou publicly reported that the @anthropic-ai/claude-code npm package exposed the full Claude Code source through a .map file and downloadable archive. The disclosure highlighted leaked architectural details, internal tools, slash commands, feature flags, and authentication-related logic.

Anthropic publishes Claude Code v2.1.88 with exposed source map

Anthropic released Claude Code CLI version 2.1.88 to npm with a packaging error that included a source map file. The map reportedly pointed to unobfuscated TypeScript source hosted on Anthropic-controlled storage, exposing nearly 2,000 files and more than 512,000 lines of code.

SOURCE COVERAGE

Sources

29 references tracked. Mallory keeps watching after this page renders.

29 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Anthropic Claude Code CLI Source Exposed Through npm Source Map | Mallory