The post Claude Code CLI Exposed via npm Source Map Error – Bitcoin News appeared on BitcoinEthereumNews.com. Claude Code npm Leak Reveals Unreleased Features IncludingThe post Claude Code CLI Exposed via npm Source Map Error – Bitcoin News appeared on BitcoinEthereumNews.com. Claude Code npm Leak Reveals Unreleased Features Including

Claude Code CLI Exposed via npm Source Map Error – Bitcoin News

2026/04/01 09:03
Okuma süresi: 4 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen crypto.news@mexc.com üzerinden bizimle iletişime geçin.

Claude Code npm Leak Reveals Unreleased Features Including KAIROS, BUDDY, and Agent Swarms

The company confirmed the incident on March 31, 2026, speaking with Venture Beat, attributing it to human error in the release packaging process. Version 2.1.88 of @anthropic-ai/claude-code shipped with a 59.8 MB Javascript source map file. Basically a debugging artifact that mapped minified production code back to the original Typescript, which pointed directly to a publicly accessible zip archive sitting on Anthropic‘s own Cloudflare R2 storage bucket.

Nobody had to hack anything. The file was just there.

Security researcher Chaofan Shou, an intern at blockchain security firm Fuzzland, spotted the issue and posted the direct bucket link on X. Within hours, mirrored repositories appeared on Github, some accumulating tens of thousands of stars before Anthropic’s DMCA takedowns hit. Community members had already begun stripping telemetry, flipping hidden feature flags, and drafting clean-room reimplementations in Python and Rust to sidestep copyright concerns.

The root cause was straightforward: Bun’s bundler generates source maps by default, and no build step excluded or disabled the debug artifact before publishing. A missing entry in .npmignore or the files field in package.json would have prevented the whole thing.

What developers found inside was detailed. The ~1,900 Typescript files covered tool execution logic, permission schemas, memory systems, telemetry, system prompts, and feature flags — a full engineering view of how Anthropic builds a production-grade agentic coding tool. Telemetry scans prompts for profanity as a frustration signal but does not log full user conversations or code. An “undercover mode” instructs the AI to remove references to internal codenames and project details from git commits and pull requests.

Several unreleased features sat behind flags. KAIROS is described as an always-on background daemon that watches files, logs events, and runs a “dreaming” memory-consolidation process during idle time. BUDDY is a terminal pet with 18 species — including capybara — carrying stats like DEBUGGING, PATIENCE, and CHAOS. COORDINATOR MODE lets a single agent spawn and manage parallel worker agents. ULTRAPLAN schedules 10- to 30-minute remote multi-agent planning sessions.

Anthropic told Venture Beat the incident involved no sensitive customer data, no credentials, and no compromise of model weights or inference infrastructure. “This was a release packaging issue caused by human error,” the company said, adding that it is rolling out measures to prevent a repeat.

Those measures may need to move quickly. This is the second time the same mistake has happened. A nearly identical source-map leak occurred with an earlier version of Claude Code in February 2025.

The March 31 incident also landed alongside a separate npm supply-chain attack on the axios package, active between 00:21 and 03:29 UTC. Developers who installed or updated Claude Code via npm during that window are advised to audit their dependencies and rotate credentials. Anthropic recommends its native installer over npm going forward.

Context matters here. Five days earlier, on March 26, a CMS misconfiguration at Anthropic exposed roughly 3,000 internal files covering details on the unreleased “Claude Mythos” model, also attributed to human error. Two significant accidental disclosures in less than a week raises questions about release hygiene at a company whose tools are actively used to write and ship code at scale.

The leaked source code remains available in archived and mirrored forms despite active takedown enforcement. Anthropic has not published a broader post-mortem or public statement beyond its comment to Venture Beat.

No user data was exposed. The core Claude models are unaffected. The blueprint for building a competitor to Claude Code, however, is now considerably easier to assemble.

FAQ 🔎

  • Q: Was the Claude Code source code leak a hack? No — Anthropic confirmed the exposure was a packaging error, not a security breach or unauthorized access.
  • Q: What was actually exposed in the Anthropic npm leak? Approximately 512,000 lines of TypeScript covering the Claude Code CLI, including telemetry, feature flags, hidden features, and agent architecture — not model weights or customer data.
  • Q: Is my data at risk from the Claude Code npm incident? Anthropic says no user data or credentials were exposed; developers who installed via npm during the concurrent axios supply-chain attack window should audit dependencies and rotate credentials.
  • Q: Has Anthropic leaked source code before? Yes — a nearly identical source-map leak involving an earlier Claude Code version occurred in February 2025, making this the second such incident in roughly 13 months.

Source: https://news.bitcoin.com/anthropic-source-code-leak-2026-claude-code-cli-exposed-via-npm-source-map-error/

Piyasa Fırsatı
MapNode Logosu
MapNode Fiyatı(MAP)
$0.00225
$0.00225$0.00225
+0.44%
USD
MapNode (MAP) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen crypto.news@mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Why LYNO’s Presale Could Trigger the Next Wave of Crypto FOMO After SOL and PEPE

Why LYNO’s Presale Could Trigger the Next Wave of Crypto FOMO After SOL and PEPE

The post Why LYNO’s Presale Could Trigger the Next Wave of Crypto FOMO After SOL and PEPE appeared on BitcoinEthereumNews.com. Cryptocirca has never been bereft of hype cycles and fear of missing out (FOMO). The case of Solana (SOL) and Pepe (PEPE) is one of the brightest examples that early investments into the correct projects may yield the returns that are drifting. Today there is an emerging rival in the limelight—LYNO. LYNO is in its presale stage, and already it is being compared to former breakout tokens, as many investors are speculating that LYNO will be the next big thing to ignite the market in a similar manner. Early Bird Presale: Lowest Price LYNO is in the Early Bird presale and costs only $0.050 for each token; the initial round will rise to $0.055. To date, approximately 629,165.744 tokens have been sold, with approximately $31,458.287 of that amount going towards the $100,000 project goal.  The crypto presales allow investors the privilege to acquire tokens at reduced prices before they become available to the general market, and they tend to bring substantial returns in the case of great fundamentals. The final goal of the project: 0.100 per token. This gradual development underscores increasing investor confidence and it brings a sense of urgency to those who wish to be first movers. LYNO’s Edge in a Competitive Market LYNO isn’t just another presale token—it’s a powerful AI-driven cross-chain arbitrage platform designed to deliver real utility and long-term growth. Operating across 15+ blockchains, LYNO’s AI engine analyzes token prices, liquidity, volume, and gas fees in real-time to identify the most profitable trade routes. It integrates with bridges like LayerZero, Wormhole, and Axelar, allowing assets to move instantly across networks, so no opportunity is missed.  The platform also includes community governance, letting $LYNO holders vote on protocol upgrades and fee structures, staking rewards for long-term investors, buyback-and-burn mechanisms to support token value, and audited smart…
Paylaş
BitcoinEthereumNews2025/09/18 16:11
The $55 Oil Trade Is Still on the Table, but Brent’s Chart Has Conditions

The $55 Oil Trade Is Still on the Table, but Brent’s Chart Has Conditions

The post The $55 Oil Trade Is Still on the Table, but Brent’s Chart Has Conditions appeared on BitcoinEthereumNews.com. The oil price surged on April 2 as Brent
Paylaş
BitcoinEthereumNews2026/04/02 18:30
Covéa Chooses Shift Technology as Strategic Partner for Fraud and Risk Management

Covéa Chooses Shift Technology as Strategic Partner for Fraud and Risk Management

Covéa has selected Shift Technology as a long-term partner to support a consistent and shared view of risk from policy inception through to claims settlement The
Paylaş
ffnews2026/04/02 07:00

Trade GOLD, Share 1,000,000 USDT

Trade GOLD, Share 1,000,000 USDTTrade GOLD, Share 1,000,000 USDT

0 fees, up to 1,000x leverage, deep liquidity