Anthropic accidentally leaks Claude Code source in npm slip
Anthropic confirmed yesterday that ‘human error’ led to the leak of much of the source code of its star product Claude Code. Read more: Anthropic accidentally leaks Claude Code source in npm slip
Anthropic confirmed yesterday that ‘human error’ led to the leak of much of the source code of its star product Claude Code.
Anthropic has accidentally leaked the source code of its Claude Code agent after a misconfigured software package exposed it to the public. It follows a separate incident last week where Fortune said the company had accidentally leaked thousands of files.
The leak was spotted on Tuesday by security researcher Chaofan Shou, according to The Register, who found that the official npm package for Claude Code had shipped with a map file referencing an unobfuscated TypeScript source. Chaofan Shou proceeded to announce his find on X, sparking a flurry of activity.
That file pointed to a zip archive stored on Anthropic’s Cloudflare R2 storage bucket, which anyone could download and decompress. The archive reportedly contained some 1,900 TypeScript files totalling more than 512,000 lines of code, including full libraries of slash commands and built-in tools.
Within hours, a copy of the code was uploaded to GitHub, where it was ‘forked’ more than 41,500 times, according to The Register, effectively ensuring that the exposure could not easily be undone.
“Earlier today, a Claude Code release included some internal source code,” an Anthropic spokesperson told SiliconRepublic.com. “No sensitive customer data or credentials were involved or exposed. This was a release packaging issue caused by human error, not a security breach. We’re rolling out measures to prevent this from happening again.”
The incident comes just days after Fortune reported that Anthropic had accidentally made thousands of files publicly available, including a draft blogpost describing an upcoming model known internally as both “Mythos” and “Capybara” – one that the document said presents cybersecurity risks.
The Register cited software engineer Gabriel Anhaia, who published a detailed analysis of the exposed code, saying the incident should serve as a cautionary tale for development teams everywhere.
“Apparently, a source map file was included in the npm package. Source maps are meant for debugging – they map minified/bundled code back to the original source,” Anhaia wrote in his analysis of the Claude Code leak. “Including one in a production npm publish effectively ships your entire codebase in readable form.
“This is a reminder for every engineering team: check your build pipeline. Make sure .map files are excluded from your publish configuration. A single misconfigured .npmignore or files field in package.json can expose everything,”
As experts and commentators pored through the now available source code, there seemed to be consensus that they were impressed with what they saw.
“Notice no one said the code is slop,” said prominent US tech blogger Robert Scoble in a social media post. “In every painful moment there are always gifts. The gift is that we all know now that Anthropic’s code is pretty damn good.”
However it also clear that the leak is a gift to its powerful competitors who are vying to compete with one of Anthropic’s most successful products, and have been given an inside view of what’s behind it.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
Silicon Republic
https://www.siliconrepublic.com/machines/anthropic-accidentally-leaks-claude-code-source-in-npm-slipSign in to highlight and annotate this article

Conversation starters
Daily AI Digest
Get the top 5 AI stories delivered to your inbox every morning.
More about
claudeproductclaude codeA 6-point scorecard for AI-ready product pages - Search Engine Land
<a href="https://news.google.com/rss/articles/CBMid0FVX3lxTE1oeVo3cDVwcDBmMXpJeDhrRmlqTEJXTmw0dmk3bE94OXR6MENJNThyYjZaOWlYOVZacC1TLTd6UFlOYTJ2MWU5REtYd1RwY3UyemdTWUUwcUNab29kaVhjUWgyaDBkR2ctSEpodThnSEJkaTJzMHhV?oc=5" target="_blank">A 6-point scorecard for AI-ready product pages</a> <font color="#6f6f6f">Search Engine Land</font>
Anthropic has ‘come to copyright’ epiphany after Claude code leak - Startup Daily
<a href="https://news.google.com/rss/articles/CBMirAFBVV95cUxPdWs1cUkxdkI1SDJhLWxoWElDY1drNXJyN2xsU3Q1T1VSVXI0NEFzUWpQa0hqQTRuWW1tMnVKSjdiaGZyb1JkOW5kUENXNUl4WWlfTkg4WThPNk5fVEltZEJaZHI1TFBjd3h6bktFMWF4SUR2UmQwMDZLNHpZRFZsT0V1aGZKSG9fRXl3SVA3S0d0Q3k4aF94V2dQZUJudGJKb2ZQcW1qV0d2Q0ot?oc=5" target="_blank">Anthropic has ‘come to copyright’ epiphany after Claude code leak</a> <font color="#6f6f6f">Startup Daily</font>
Exclusive | The Sudden Fall of OpenAI’s Most Hyped Product Since ChatGPT - WSJ
<a href="https://news.google.com/rss/articles/CBMiogNBVV95cUxQUlF1Vm9tRDZuOHVqUW9fMlYtNXdtT083OVVIWVdIdFUtOVVkdF9PQ0xiSTE0SXhjOXBwT2hqQU5xc0p3TkdfTVFBWkdyRDNTaGV4TDFRQUFDc3Z4Tlh1U0xPOVpSMzdrc2NoSjZfY21aWnZ0LWMwVHFsRHJUNHVhOWF1Z0FvOTBtNnZseEdDMG5STm85aVozeXdfRmxsNUlsbEZhb0hjNm5iRy1pUWJGd1ZxaUZrWXU5TUxmdmVjd3hpRmQ1NDRKZUQ0NlRLYUZydUo5VWFZSUJZMTJ5UllqczA0bnlvc2lEQnRVSXBvdDVBbVhScnR5clhRdm5OejFqMnpBTUdaOVE5TDRJU2JOOEpEWVIxa3psaXlhTlZoYVpCZGRhTDN0a19rTC15VWpsczV1VExUbTl5cU5OV3dLajE4VGlYUm4tY0VIWjNza2V2MU8wVjYzb0ZkbjlqVmdaSUM0WWlyaDBXNlFmaGM2dnpCZkZrd1VRNTFRQnZrNVFmdGxUeWFYUzB0M1FmeG1ObW1SYTBXTFF3OGNLNldpRXZ3?oc=5" target="_blank">Exclusive | The Sudden Fall of OpenAI’s Most Hyped Product Since ChatGPT</a> <font color="#6f6f6f">WSJ</font>
Knowledge Map
Connected Articles — Knowledge Graph
This article is connected to other articles through shared AI topics and tags.
More in AI Tools
SEO leads martech replacements, but not for the reason you think - Search Engine Land
<a href="https://news.google.com/rss/articles/CBMidEFVX3lxTFA5Umh0SDRTTXZsRlpGNXVWcHJRVTZKdENLdDFyWC1qeUJXbmhRbzRWZWhfZTVnUDJrNEZtU2xnNHpiS3hrQWE0czVwdTVlbzJxVjduQnlFenJlSWg4eUxtWXdmWGQ3eFhRT2k3WkZpYmNSZTdV?oc=5" target="_blank">SEO leads martech replacements, but not for the reason you think</a> <font color="#6f6f6f">Search Engine Land</font>

Lipschitz Dueling Bandits over Continuous Action Spaces
arXiv:2604.00523v1 Announce Type: cross Abstract: We study for the first time, stochastic dueling bandits over continuous action spaces with Lipschitz structure, where feedback is purely comparative. While dueling bandits and Lipschitz bandits have been studied separately, their combination has remained unexplored. We propose the first algorithm for Lipschitz dueling bandits, using round-based exploration and recursive region elimination guided by an adaptive reference arm. We develop new analytical tools for relative feedback and prove a regret bound of $\tilde O\left(T^{\frac{d_z+1}{d_z+2}}\right)$, where $d_z$ is the zooming dimension of the near-optimal region. Further, our algorithm takes only logarithmic space in terms of the total time horizon, best achievable by any bandit algorith
AI use rises in health systems, but many patients still struggle to access care - Managed Healthcare Executive
<a href="https://news.google.com/rss/articles/CBMixAFBVV95cUxOUDMwd2dZWlJ1LUpGcHNJZDJFamhKMTJDN0pIUF8tSGVkblZSWThlb2VHNzZWei1jSWtTZWVidEJFdnA2NlRuYXJGVGI2Vk9ZelY0V3Bmb3Naa0QyMjZwOC1MTkRlQUZPdmhXamJYWW1wdmxHUlB0czFsRHZ0RmptcWtvMnpKdWt6UGM1NEp5dTJTRTRzeW5sLUJuWnR0N09IOTEwNGtueUVETTRIYzBNSDMxVFU5WkdFazJscjgxV1ctcl9X?oc=5" target="_blank">AI use rises in health systems, but many patients still struggle to access care</a> <font color="#6f6f6f">Managed Healthcare Executive</font>
Discussion
Sign in to join the discussion
No comments yet — be the first to share your thoughts!