Sev0AI security incidents, tracked

All incidents / Leaky AI product

Anthropic accidentally published Claude Code's full source code to npm

Anthropic, disclosed Mar 2026. Leaky AI product Data exposed Medium

A packaging mistake shipped a complete source map inside a public Claude Code release, exposing about 500,000 lines of the agent's code, including its permission system and unreleased features. The code was mirrored widely within hours.

Disclosed
Mar 2026
Organization
Anthropic
Vendor
Anthropic
Product
Claude Code
Kind of AI
Coding agent
AI's role
AI was the target
How it happened
Leaky AI product: Accidental publication
Harm
Data exposed
Data involved
Source code
Reach
One organization
Severity
Medium
Model at fault
No
Status
Confirmed

Sources

  1. https://guardion.ai/ai-incidents/anthropic-claude-code-source-map-leak

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Anthropic accidentally published Claude Code's full source code to npm", https://sev0.fyi/incidents/2026-03-01-anthropic-claude-code-source-leak/