Sev0

AI security incidents, tracked

All incidents / Leaky AI product

Anthropic accidentally published Claude Code's full source code to npm

Anthropic, disclosed 31 Mar 2026. Leaky AI product Data exposed Medium

A packaging mistake shipped a complete source map inside a public Claude Code release on npm, exposing about 512,000 lines of the agent's code, including its permission system and unreleased features. Anthropic confirmed it was human error; the code was mirrored widely within hours.

Disclosed
31 Mar 2026
Organization
Anthropic
Vendor
Anthropic
Product
Claude Code
Type of AI
Coding assistant
How it happened
Leaky AI product: Accidental publication
Harm
Data exposed
Data involved
Source code
Reach
One organization
Severity
Medium
Model at fault
No
Status
Confirmed

Sources

  1. https://thehackernews.com/2026/04/claude-code-tleaked-via-npm-packaging.html
  2. https://venturebeat.com/technology/claude-codes-source-code-appears-to-have-leaked-heres-what-we-know
  3. https://cybernews.com/security/anthropic-claude-code-source-leak/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Anthropic accidentally published Claude Code's full source code to npm", https://sev0.fyi/incidents/2026-03-31-anthropic-claude-code-source-leak/