Claude Code Source Leak 2026: The Complete Guide to What Was Exposed

Last updated: March 2026 On March 31, 2026, a 57 MB source map file shipped inside the @anthropic-ai/claude-code npm package exposed the entire TypeScript source code of Claude Code — 1,900 files and 512,000+ lines of code. The leak revealed unreleased features (KAIROS always-on agent, autoDream memory consolidation, ULTRAPLAN, Buddy System), future model codenames (Opus … Read more

Axios npm Attack: RAT Hits 100M-Download Package on Claude Code Leak Day

Last updated: March 2026 On March 31, 2026, attackers compromised the npm account of Axios’s lead maintainer and published two malicious versions (1.14.1 and 0.30.4) of the HTTP client library used by over 100 million projects weekly. The poisoned packages silently installed a cross-platform Remote Access Trojan (RAT) via a hidden dependency called plain-crypto-js. The … Read more

Claude Code Source Code Leaked — 7 Things We Learned

Claude Code Source Code Leaked

Last updated: March 2026 On March 31, 2026, security researcher Chaofan Shou discovered that Anthropic accidentally shipped a source map file inside the @anthropic-ai/claude-code npm package (version 2.1.88). The 57 MB file exposed the full TypeScript source code of Claude Code — roughly 1,900 files and 512,000+ lines — including unreleased features, internal codenames, system … Read more