Anthropic coding tool exposes full source code again after packaging error

April 1, 2026 Anthropic has inadvertently exposed the full source code of its Claude Code tool for the second time in a year due to a packaging mistake in its public release. The leak included 1,906 proprietary source files covering internal APIs, telemetry systems, encryption tools and communication protocols.

The issue was discovered on March 31, 2026 by security researcher Chaofan Shou, who found that a 60MB source map file (cli.js.map) had been included in the tool’s npm package. That file allowed anyone to reconstruct the original TypeScript codebase from the distributed build.

Source maps are typically used during development to debug software by linking compiled code back to its original form. However, they are not intended for production releases, as they effectively expose the full underlying code. In this case, the file also referenced unobfuscated source files hosted in Anthropic’s cloud storage, making the code directly downloadable.

The exposed package, Claude Code version 2.1.88, was published to npm, a widely used public software registry. Within hours of discovery, the leaked codebase was archived on GitHub, where it quickly gained more than 1,100 stars and 1,900 forks, increasing its visibility and distribution.

This is not the first occurrence. An earlier version of Claude Code was exposed in February 2025 due to the same issue, after which Anthropic removed the affected release and deleted the source map. The recurrence suggests a gap in release controls rather than a one-off mistake.

The exposure does not include model weights or user data, and there is no indication of a breach involving customer information. However, the leak reveals the internal structure of the tool, including how it handles telemetry, security layers, and inter-process communication – details typically kept private.

For developers, this distinction matters. While user data remains unaffected, access to internal implementation details can provide insight into system design and security mechanisms, which may carry competitive or operational implications.

Anthropic has not issued a public statement on the incident. The discovery is likely to draw scrutiny around software release practices, particularly as AI development tools are increasingly used in enterprise environments where code integrity and intellectual property protection are critical.



Top Stories

Related Articles

April 3, 2026 The CEO of NYC Health + Hospitals says artificial intelligence could replace a significant portion of radiology more...

April 3, 2026 OpenAI has signed Smartly as its first dedicated adtech partner to refine how advertising appears in ChatGPT. more...

April 2, 2026 Researchers from California Institute of Technology and start-up Oratomic have demonstrated a new error-correction approach that could more...

April 2, 2026 AMD has agreed to acquire Intel in an all-stock transaction that would combine the two long-time x86 more...

Picture of Mary Dada

Mary Dada

Mary Dada is the associate editor for Tech Newsday, where she covers the latest innovations and happenings in the tech industry’s evolving landscape. Mary focuses on tech content writing from analyses of emerging digital trends to exploring the business side of innovation.
Picture of Mary Dada

Mary Dada

Mary Dada is the associate editor for Tech Newsday, where she covers the latest innovations and happenings in the tech industry’s evolving landscape. Mary focuses on tech content writing from analyses of emerging digital trends to exploring the business side of innovation.

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn