Anthropic leaks Claude Code source via npm map
Anthropic accidentally exposed the full source code for its agentic CLI tool, Claude Code, through an unprotected npm source map file. The leak revealed sensitive internal models, telemetry tracking metrics, and proprietary system prompts.
This incident highlights a critical oversight in JavaScript deployment pipelines where source maps are left accessible in production releases. Exposing system prompts gives competitors a direct look into Anthropic's agentic reasoning and instruction tuning strategies. The revelation of internal models and tracking metrics raises questions about what telemetry is collected by default in developer tools. It serves as a stark reminder to double-check build processes and npm publication configurations to prevent accidental intellectual property exposure.
DISCOVERED
6d ago
2026-04-06
PUBLISHED
6d ago
2026-04-06
RELEVANCE
AUTHOR
Wes Roth