Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Anthropic’s Claude Code Source Leak via npm Registry

Anthropic’s Claude Code Source Leak via npm Registry

Posted on March 31, 2026 By CWS

Anthropic’s Claude Code, a proprietary CLI tool, has had its TypeScript source code inadvertently exposed due to a misconfigured npm package. This exposure was discovered when a security researcher found a leaked .map file that referenced the unprotected codebase on Anthropic’s cloud infrastructure.

Details of the Security Breach

On March 31, 2026, Chaofan Shou, a security researcher, publicly disclosed the leak, revealing that the @anthropic-ai/claude-code npm package contained a source map file. This file provided a direct reference to the complete, unminified TypeScript source, which was downloadable as a ZIP file from Anthropic’s R2 cloud bucket.

The codebase, now preserved in a public GitHub repository, includes around 1,900 files and over 512,000 lines of TypeScript code. It encompasses critical parts of the Claude Code CLI tool, utilizing the Bun runtime and a React + Ink terminal UI framework.

Scope and Impact of the Leak

The leaked files are comprehensive, involving every essential subsystem of the Claude Code. Key components include the QueryEngine.ts file, which contains approximately 46,000 lines of code and handles the core LLM API engine, and Tool.ts, with around 29,000 lines, defining agent tool types and permissions.

Additionally, the architecture reveals about 40 agent tools and approximately 85 slash commands, covering various functionalities such as Git workflows and multi-agent orchestration. Internal feature flags like PROACTIVE and VOICE_MODE, indicative of unreleased features, were also disclosed.

Understanding the Source Map Vulnerability

Source maps are intended for debugging by mapping compiled JavaScript back to its original source. However, when incorrectly included in npm production releases, they can expose proprietary code, bypassing obfuscation efforts. This isn’t the first instance for Anthropic; a similar issue occurred in early 2025.

The breach poses significant intellectual property risks, as the exposed code includes internal API logic and undisclosed features. Anthropic has yet to release a public statement addressing the incident.

Developers using Claude Code should keep an eye on Anthropic’s security advisories and ensure they are using patched npm releases. It is advisable to avoid third-party mirrors of the leaked source code.

For more updates on cybersecurity, follow us on Google News, LinkedIn, and X. Reach out if you have a story to share.

Cyber Security News Tags:Anthropic, Bun runtime, Claude Code, cloud storage, Cybersecurity, data breach, developer tools, Ink framework, intellectual property, npm package, npm registry, React, security advisories, source leak, source maps, TypeScript

Post navigation

Previous Post: TeamPCP Exploits AWS for Data Breaches in Latest Cyberattack
Next Post: AI Arms Race: Prioritizing Unified Exposure Management

Related Posts

Critical Security Updates for Notepad++ to Block Exploits Critical Security Updates for Notepad++ to Block Exploits Cyber Security News
CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks Cyber Security News
EU’s Digital Age App Vulnerable to Quick Hacking EU’s Digital Age App Vulnerable to Quick Hacking Cyber Security News
Critical Flaw in Argo CD Exposes Sensitive Kubernetes Data Critical Flaw in Argo CD Exposes Sensitive Kubernetes Data Cyber Security News
Massive Android Ad Fraud ‘IconAds’ Leverages Google Play to Attack Phone Users Massive Android Ad Fraud ‘IconAds’ Leverages Google Play to Attack Phone Users Cyber Security News
Microsoft Details Scattered Spider TTPs Observed in Recent Attack Chains Microsoft Details Scattered Spider TTPs Observed in Recent Attack Chains Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • MikroTik RouterOS Vulnerability Exposes Critical Risks
  • Over 500,000 Active Credentials Found on GitHub
  • Urgent Fixes Issued for Cisco SD-WAN Critical Flaw
  • Google Introduces Gemini 4 Argon to Cybersecurity Experts
  • Google Unveils Argon AI Model for Cybersecurity Experts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • MikroTik RouterOS Vulnerability Exposes Critical Risks
  • Over 500,000 Active Credentials Found on GitHub
  • Urgent Fixes Issued for Cisco SD-WAN Critical Flaw
  • Google Introduces Gemini 4 Argon to Cybersecurity Experts
  • Google Unveils Argon AI Model for Cybersecurity Experts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark