Image Credentials: Image Title: Anthropic Accidentally Exposes Claude Code Source Following Packaging Error Source: (sora.openai) Date: March 2025. Attribution: This image was created using AI-generated imagery (sora.openai) and does not depict a real-world scene.
By Open Chronicle Staff with Agencies
SAN FRANCISCO — Anthropic, the high-profile artificial intelligence firm backed by Amazon and Google, inadvertently exposed the full source code for its flagship command-line tool, Claude Code, on Tuesday. The leak, attributed to a “basic packaging oversight,” allowed developers and researchers to reconstruct the human-readable TypeScript code of the agentic AI platform.
The exposure was first identified by security researcher Chaofan Shau, who discovered that a 60MB source file map, titled cli.js.map, had been bundled within the tool’s public npm package. The npm registry is the world’s largest repository for software packages, used by millions of developers to distribute and install tools.
Claude code source code has been leaked via a map file in their npm registry!
Code: https://t.co/jBiMoOzt8G pic.twitter.com/rYo5hbvEj8
— Chaofan Shou (@Fried_rice) March 31, 2026
The “Map” to the Codebase
In software development, a source map is a file that maps compressed, production-ready code back to its original, human-readable source. While essential for internal debugging, these files are strictly intended to be stripped from public releases to protect intellectual property and internal security logic.
The presence of the map in version v2.1.88, released on March 31, effectively handed over the “blueprints” for 1,906 proprietary source files. Within hours of the discovery, thousands of developers reportedly mirrored and reposted the approximately 512,000-line codebase to GitHub.
What Was Revealed?
The leak provided an unprecedented look into the “internal memory architecture” and engineering philosophy behind one of the industry’s most advanced AI coding assistants. According to media reports and analysis by BlockBeats, the exposed files detailed:
-
Internal API structures and communication protocols.
-
Telemetry systems and usage tracking mechanisms.
-
Encryption methods and inter-process communication logic.
Despite the scale of the intellectual property exposure, Anthropic and independent researchers emphasized that the leak was confined to the client-side tool. “The leak only affects part of the Claude Code tool itself and does not include user data or the AI’s core systems,” noted a report from Odaily. Personal chats and private information remain secure, as those are handled by Anthropic’s protected back-end servers.
A Recurring Oversight
Industry experts have expressed surprise at the nature of the leak, with some suggesting such a mistake should never occur in a finished enterprise product. This marks the second time in just over a year that Anthropic has suffered a source map exposure.
In February 2025, an early version of the same tool was leaked under nearly identical circumstances. While Anthropic moved quickly at the time to purge the files from the npm registry, the recurrence of the error has raised questions regarding the company’s internal deployment and security auditing practices.
Anthropic has not yet issued a formal statement regarding the long-term implications of the proprietary logic now being in the public domain. However, the company is expected to push an emergency update to the npm registry to prevent further downloads of the compromised version.