Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Anthropic’s Claude Code Source Leak via npm Registry

Anthropic’s Claude Code Source Leak via npm Registry

Posted on March 31, 2026 By CWS

Anthropic’s Claude Code, a proprietary CLI tool, has had its TypeScript source code inadvertently exposed due to a misconfigured npm package. This exposure was discovered when a security researcher found a leaked .map file that referenced the unprotected codebase on Anthropic’s cloud infrastructure.

Details of the Security Breach

On March 31, 2026, Chaofan Shou, a security researcher, publicly disclosed the leak, revealing that the @anthropic-ai/claude-code npm package contained a source map file. This file provided a direct reference to the complete, unminified TypeScript source, which was downloadable as a ZIP file from Anthropic’s R2 cloud bucket.

The codebase, now preserved in a public GitHub repository, includes around 1,900 files and over 512,000 lines of TypeScript code. It encompasses critical parts of the Claude Code CLI tool, utilizing the Bun runtime and a React + Ink terminal UI framework.

Scope and Impact of the Leak

The leaked files are comprehensive, involving every essential subsystem of the Claude Code. Key components include the QueryEngine.ts file, which contains approximately 46,000 lines of code and handles the core LLM API engine, and Tool.ts, with around 29,000 lines, defining agent tool types and permissions.

Additionally, the architecture reveals about 40 agent tools and approximately 85 slash commands, covering various functionalities such as Git workflows and multi-agent orchestration. Internal feature flags like PROACTIVE and VOICE_MODE, indicative of unreleased features, were also disclosed.

Understanding the Source Map Vulnerability

Source maps are intended for debugging by mapping compiled JavaScript back to its original source. However, when incorrectly included in npm production releases, they can expose proprietary code, bypassing obfuscation efforts. This isn’t the first instance for Anthropic; a similar issue occurred in early 2025.

The breach poses significant intellectual property risks, as the exposed code includes internal API logic and undisclosed features. Anthropic has yet to release a public statement addressing the incident.

Developers using Claude Code should keep an eye on Anthropic’s security advisories and ensure they are using patched npm releases. It is advisable to avoid third-party mirrors of the leaked source code.

For more updates on cybersecurity, follow us on Google News, LinkedIn, and X. Reach out if you have a story to share.

Cyber Security News Tags:Anthropic, Bun runtime, Claude Code, cloud storage, Cybersecurity, data breach, developer tools, Ink framework, intellectual property, npm package, npm registry, React, security advisories, source leak, source maps, TypeScript

Post navigation

Previous Post: TeamPCP Exploits AWS for Data Breaches in Latest Cyberattack
Next Post: AI Arms Race: Prioritizing Unified Exposure Management

Related Posts

Critical Flaw in Next-Mdx-Remote Threatens React Servers Critical Flaw in Next-Mdx-Remote Threatens React Servers Cyber Security News
Security Vulnerability in Composer Exposes Sensitive Files Security Vulnerability in Composer Exposes Sensitive Files Cyber Security News
Sensitive Leaks Reveal Anthropic’s New AI Model ‘Claude Mythos’ Sensitive Leaks Reveal Anthropic’s New AI Model ‘Claude Mythos’ Cyber Security News
Claude AI Enhances Microsoft Word with New Beta Integration Claude AI Enhances Microsoft Word with New Beta Integration Cyber Security News
Qilin Ransomware Disables EDR Systems with Malicious DLL Qilin Ransomware Disables EDR Systems with Malicious DLL Cyber Security News
Attackers Abuse Discord to Deliver Clipboard Hijacker That Steals Wallet Addresses on Paste Attackers Abuse Discord to Deliver Clipboard Hijacker That Steals Wallet Addresses on Paste Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Over 543,000 GitHub Credentials Remain Vulnerable
  • US Treasury Targets ATM Malware Network in Sanctions
  • MikroTik RouterOS Vulnerability Exposes Critical Risks
  • Over 500,000 Active Credentials Found on GitHub
  • Urgent Fixes Issued for Cisco SD-WAN Critical Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Over 543,000 GitHub Credentials Remain Vulnerable
  • US Treasury Targets ATM Malware Network in Sanctions
  • MikroTik RouterOS Vulnerability Exposes Critical Risks
  • Over 500,000 Active Credentials Found on GitHub
  • Urgent Fixes Issued for Cisco SD-WAN Critical Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark