Skip to content

Anthropic Leaks Claude Code Source via npm Source Map

devMar 31, 2026252

Anthropic accidentally exposed Claude Code's full TypeScript source when a misconfigured npm source map published roughly 512,000 lines and about 2,000 files. The leak revealed internal agent orchestration, memory-management systems, and unreleased safety and feature code. Anthropic confirmed no customer data or model weights were exposed. Researchers and competitors are already reverse-engineering the code, producing fixes and insights that could accelerate rival development.

Key Highlights

Anthropic accidentally published 512,000 lines of Claude Code TypeScript via npm.
Leak exposed internal agent features and safety harnesses, not model weights.
Developers are reverse-engineering the code and issuing quick community fixes.
2 sources