Anthropic Accidentally Leaks Claude Code Source Code via npm Registry

An Anthropic employee accidentally leaked Claude Code source code through a map file published to the npm registry. Security researcher Chaofan Shou posted the discovery on X, where it was viewed more than 30 million times. The leak exposed internal implementation details of one of the most widely used AI coding assistants.

Anthropic Accidentally Leaks Claude Code Source Code via npm Registry

Anthropic accidentally exposed source code tied to Claude Code after an employee published a map file to the npm registry, revealing internal implementation details of the AI coding assistant. The leak was identified by security researcher Chaofan Shou, who posted the discovery on X, where the thread drew more than 30 million views.

The incident matters because Claude Code is one of the better-known tools in the fast-growing market for AI coding assistants. These tools help developers write, edit, and reason about code by connecting a large language model to the files and commands in a local development environment.

⚡ New to this?

This is about an accidental software leak involving Claude Code, Anthropic’s AI assistant for writing and working with code. The npm registry is a public software package library, and a map file is a developer file that can sometimes point back to source code.

Non-experts should care because AI coding tools are increasingly used inside real development environments, where they can see files, commands, and project context. When internal code or design details leak, it can reveal how the assistant works under the hood and help outsiders study its behavior.

🦞 OpenClaw angle

If you run Claude Code on your OpenClaw VM, the leaked source code doesn't create a direct vulnerability for your setup. But it does reveal how Claude Code manages context, compaction, and tool calls internally — information that could inform future prompt injection attacks against Claude-powered agents.

The npm registry, which is widely used to distribute JavaScript packages, is a common place for software teams to publish code and related build artifacts. A map file is usually a source map, a file that helps developers trace compiled or transformed code back to its original source. Source maps are meant to make debugging easier, but if they are published publicly with sensitive paths or embedded source references, they can expose more than intended.

In this case, the leaked file appears to have revealed internal code associated with Claude Code rather than just metadata. That gives outside researchers a look at how Anthropic structured parts of the product and how the assistant handles some of its internal logic.

Security disclosures like this are not unusual in modern software development. Large products often include a mix of open-source dependencies, internal tooling, and generated artifacts, and a single mistake in packaging or publishing can expose details that were never meant to be public. When the product in question is an AI assistant that interacts with code, those details can be especially sensitive, because they may show how the system decides what context to keep, what to discard, and how it issues tool calls.

Chaofan Shou’s post turned the leak into a widely discussed issue on social media, which is often how these incidents spread before a company publishes its own account. That kind of public attention can accelerate external review, but it also means leaked material can circulate quickly before the vendor has time to assess the full scope.

For Anthropic, the practical question is not just what was exposed, but what the exposed code can teach observers about Claude Code’s internal behavior. AI coding assistants are frequently integrated into developer workflows with broad access to repositories, terminals, and project files, so implementation details can be useful to security researchers and, in the wrong hands, to attackers studying model behavior.

The broader pattern is familiar to anyone watching AI tooling closely: the more deeply these systems plug into developer environments, the more important their internal guardrails, packaging hygiene, and release processes become. In this case, the leak came not from the model itself, but from an ordinary publishing mistake tied to a file that should not have made it to a public registry in the first place.

Source: Cyber Security Review ↗

More from Security News