Summary

The full TypeScript source code of Anthropic’s proprietary Claude Code CLI tool was inadvertently exposed on March 31, 2026, through a misconfigured npm package. Security researcher Chaofan Shou discovered that a leaked .map file within the @anthropic-ai/claude-code npm package (version 2.1.88) referenced the complete, unobfuscated codebase — directly downloadable from Anthropic’s cloud storage.

The exposed codebase represents the entirety of Claude Code’s src/ directory: approximately 1,900 files and over 512,000 lines of code. Critical components were revealed, including the core LLM API engine (QueryEngine.ts), agent tool types and permission schemas (Tool.ts), and slash command registration logic. Details about roughly 40 agent tools, 85 slash commands, internal API client logic, OAuth 2.0 flows, multi-agent coordination, and undisclosed feature pipelines were all laid bare.

Anthropic reportedly scrambled to remove the npm package, but copies were quickly mirrored on GitHub. As of publication, Anthropic had not issued a public statement.

Source

Originally reported by Cybersecurity News and VentureBeat.

Commentary

This is a textbook example of why sourcemap files should never ship in production packages. The irony of a leading AI company — one that builds tools designed to write and audit code — getting caught by a basic build pipeline misconfiguration is not lost on the security community. The leak doesn’t expose user data, but it’s an IP nightmare for Anthropic: competitors can now study their agent architecture, tool permission model, and internal feature roadmap in detail.

For the broader ecosystem, this is a reminder that npm supply chain hygiene matters at every level. If your CI/CD pipeline doesn’t strip sourcemaps before publish, you’re one npm publish away from the same headline.

By Allan