Skip to main content

The Claude Code Leak: How a Source Map Exposed 500,000 Lines of Source

On March 31, 2026, Anthropic did something no company wants to do: it published its own source code to the world — by accident. Not through a breach, not through a rogue insider, but through a single file that slipped into a public npm package. After a researcher spotted it, the un-minified source — roughly 1,900 files and 513,000 lines of Claude Code, the very tool many of us use to write software — was mirrored to GitHub within hours. Here is what happened, why it happened, and the one lesson every developer should take from it.

Diagram: how a public npm package leaked the Claude Code source through a bundled source map
Figure 1. The leak chain: a source map bundled into the public package let anyone rebuild the original, un-minified source.

The one-line root cause: a source map

Modern JavaScript tools bundle and minify your code into a single, unreadable file for shipping. To make that file debuggable, they also emit a source map — a companion .map file that contains (or points back to) the original source so a browser or debugger can un-minify what it sees. That is wonderful in development and a disaster in a public package: a source map is your source code.

Anthropic ships Claude Code as an npm package built with Bun, which emits full source maps by default. A roughly 59.8 MB cli.js.map made it into published version 2.1.88 because *.map was never excluded from what npm packs (via .npmignore or the files field in package.json). Anyone who ran npm install @anthropic-ai/claude-code could reconstruct the original code. Anthropic described it as “a release packaging issue caused by human error, not a security breach,” adding that no sensitive customer data or credentials were involved or exposed — which, as leaks go, is the good kind of bad.

What was actually inside

The most interesting part was not the code quality — it was the roadmap peek. Analyses of the leaked source turned up dozens of hidden feature flags (reportedly around 44) and internal codenames for things that had not shipped:

  • KAIROS — a persistent, autonomous background mode: an agent that keeps working on its own rather than living only inside a single interactive session.
  • ULTRAPLAN — a delegated, longer-horizon planning mode.
  • BUDDY — the surprise entry: a Tamagotchi-style desktop pet, apparently with 18 species.
  • Model and product codenames, including Tengu (Claude Code itself), Fennec (Opus 4.6), and unreleased names like Capybara and Numbat.

If an autonomous agent that keeps working on its own (KAIROS) plus delegated planning (ULTRAPLAN) sounds familiar, it should: it is roughly the shape of the self-hosted, always-on agent setups people are already wiring up today. The leak did not expose secrets so much as it confirmed where coding agents are heading. (These come from third-party analyses of the dump, not an official roadmap — treat the details as directional, not promises.)

The cleanup made it worse before it got better

The response is where an embarrassing slip turned into a story. Anthropic issued takedown notices to scrub the leaked material, but the net was cast far too wide: the notices disabled a fork network of around 8,100 GitHub repositories, including legitimate forks of code that was already public. Claude Code lead Boris Cherny acknowledged it publicly — “this was not intentional, we’ve been working with GitHub to fix it” — and the action was narrowed from ~8,100 repos to a single repository and its 96 forks. Still, a lot of developers watched their repos vanish over a mistake that was not theirs.

Vertical timeline of the Claude Code source leak, from the March 31 2026 discovery through the walk-back of the over-broad takedown
Figure 2. The incident from discovery to walk-back.

The lesson: check your own packages

It is easy to file this under “big company, big mistake” and move on. But the exact same footgun is loaded in most of our build pipelines. If you publish an npm package, ship a desktop app, or deploy a web frontend, ask yourself whether your source maps are going out with it. A few concrete habits:

  • Decide who your source maps are for. Keep them for internal error reporting (upload to Sentry and delete), but do not pack them into a public artifact unless you mean to.
  • Use an allow-list, not a deny-list. In package.json, set the files field to the exact things you intend to publish. It is far safer than trying to remember every *.map in .npmignore.
  • Inspect the tarball before you publish. Run npm pack --dry-run (or npm publish --dry-run) and actually read the file list. The leak would have been a one-line diff to catch.
  • Turn off production source maps by default. Most bundlers make this a single config flag; opt in deliberately rather than shipping them because the tool did.
  • Scope your takedowns narrowly. If you ever do have to clean up, target specific URLs — the collateral damage from a wide net can outlast the original mistake.

Wrap-up

The Claude Code leak was low-severity by the numbers — no secrets, no customer data, and much of the tool is source-available anyway. Its real payload was a reminder. The most powerful AI lab on the planet lost control of its source to a default setting and a missing line in a config file. The same default is sitting in your build right now. Go run npm pack --dry-run and read the list.

Sources: reporting from TechCrunch, VentureBeat, The Hacker News and CNBC; technical write-ups from NodeSource, InfoQ and Layer5; and community analyses of the leaked source. Figures (~59.8 MB cli.js.map, ~1,900 files / ~513,000 lines, ~8,100 repos) reflect the most-cited numbers as of early April 2026; unreleased feature and codename details come from third-party analysis and may change.

Comments

Popular posts from this blog

Cursor AI Review: Is the AI Code Editor Worth It?

I've been using Cursor as my main code editor for a while now, and enough people have asked whether it's worth switching to that a proper review felt overdue. Short version: for me, yes — but with caveats. What is Cursor? Cursor is an AI-first code editor built as a fork of VS Code. That means every extension, theme, and keybinding you already use in VS Code works here, but with AI woven directly into the editing experience instead of bolted on as a plugin. It's made by Anysphere and can run models from OpenAI and Anthropic under the hood. What I like Tab completion is uncanny. Cursor predicts your next edit — not just the rest of the line, but the next change across the file. Once you get used to hitting Tab, going back to a plain editor feels slow. The Composer / Agent mode. You describe a change in plain language and it edits multiple files at once, showing you a diff to accept or reject. For refactors and boilerplate, this saves real time. It unde...

MacBook Pro M5 vs M5 Pro: Which One Should You Actually Buy?

Apple's latest 14-inch MacBook Pro comes in two very different flavors: the base M5 and the step-up M5 Pro . On paper they look similar — same gorgeous Liquid Retina XDR display, same design — but under the hood the gap is bigger than the names suggest. Here's a clear, no-hype breakdown, with concrete use cases so you can match the chip to your work. Quick spec comparison Spec M5 M5 Pro CPU 10-core (4 performance + 6 efficiency) Up to 18-core (6 performance + 12 efficiency) GPU 10-core Up to 20-core Neural Engine 16-core 16-core Memory bandwidth 153 GB/s 307 GB/s (roughly double) Unified memory 16 / 24 / 32 GB 24 / 48 / 64 GB Max storage Up to 4 TB SSD Up to 8 TB SSD Battery (video playback) Up to 24 hours Up to 22 hours Media engines Single encode/ProRes engine More encode/ProRes engines (higher configs) What actually changes between them More cores — the M5 Pro nearly doubles CPU cores and adds GPU cores, so sustained, multi-threaded work finishe...

Running a Server on a Mac Mini: Apple Silicon vs the Home-Server Field

The Mac Mini has quietly become one of the most interesting home-server boxes you can buy. It’s tiny, nearly silent, sips power, and Apple Silicon punches far above its weight. But is it actually the right machine to run your services on — or are you paying an Apple tax for a job a $400 mini PC does better? Let’s put it head-to-head. Why a Mac Mini makes a surprisingly good server Three things make Apple Silicon compelling as an always-on machine: Performance per watt. This is the headline. An M4 Mini idles at just a few watts and rarely pushes past ~35W under load, while delivering multicore performance that embarrasses machines drawing twice the power. Silence. Under typical server loads the fan is inaudible. If your “server” lives in a living room or bedroom, this matters more than any benchmark. Footprint. It’s the size of a coaster and runs cool, so it tucks anywhere. The honest catch It’s not all upside: macOS isn’t...