Skip to main content

Share story

Security AI

Anthropic's Claude Code Source Leak Exposes 512,000 Lines of Internal TypeScript

Anthropic's Claude Code Source Leak Exposes 512,000 Lines of Internal TypeScript Image: Primary
Anthropic accidentally shipped a 59.8 MB source map file inside version 2.1.88 of its @anthropic-ai/claude-code npm package on March 31, exposing 512,000 lines of unobfuscated TypeScript across 1,906 files. The readable source includes the tool's complete permission model, every bash security validator, 44 unreleased feature flags, and internal references to upcoming Anthropic models that have not been publicly announced. Security researcher Chaofan Shou broadcast the discovery on X at approximately 4:23 UTC. Within hours, mirror repositories had spread across GitHub. The leak is significant not only for what it exposes about Claude Code's architecture but for the attack surface it creates. Enterprise security teams using AI coding agents typically rely on behavioral obscurity as one layer of defense. With the permission model and security validators now fully readable, threat actors can map exact boundaries and attempt targeted bypasses. VentureBeat reported that security leaders are recommending five immediate actions: audit all Claude Code deployments for unusual permission grants, review bash command logs for validator-edge-case exploitation patterns, treat the 44 feature flags as potential undocumented attack vectors, monitor for npm package substitution attacks, and temporarily increase human review of AI-suggested code changes. Anthropic confirmed the exposure and pulled version 2.1.88 from npm. A patched version was released the same day. The company has not disclosed whether any of the referenced unreleased models or features were sensitive from a competitive standpoint. The incident highlights a recurring supply-chain risk in AI tooling: development artifacts, including source maps generated during build processes, can carry far more internal detail than a production release should expose. Security researchers noted that the mistake is a common one in JavaScript/TypeScript projects where source map generation is enabled by default.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from VentureBeat and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Infrastructure
AI Infrastructure

Anthropic has compute agreements worth up to $84.5 billion with SpaceX

Anthropic has agreements to pay SpaceX up to $84.5 billion for Nvidia-based computing capacity through 2029, The Information reports, citing Anthropic's IPO prospectus. Most of the agreements can be canceled with 90 days' notice. ...

Security
Security

NetScaler exploit attempts spread after proof-of-concept release

Attempts to exploit a NetScaler flaw have shifted from targeted activity to broad scanning of exposed, unpatched devices, Help Net Security reports. Researchers at Lupovis said their sensors recorded opportunistic attempts within ...

Capital Products
Capital Products

Protego Ventures closes $125 million Israeli defense tech fund

Protego Ventures has closed its first fund with $125 million in capital commitments, TechCrunch reported. The Israeli firm plans to invest $5 million to $50 million per company in defense and security technology. Ares Management c...

Products
Products

Endurance buys remaining Stöferle stakes for €18 million

Endurance Technologies acquired the remaining 32% of Germany's Stöferle Automotive GmbH and Stöferle GmbH for €18 million, giving its Italian subsidiary full ownership of both companies. A September 29 amendment brought forward a ...

AI Products
AI Products

PostHog releases Jeeves decision model with reasoning option

PostHog has released Jeeves, a 9B-parameter model for answering yes-or-no, multiple-choice, and rating questions through a Jev-compatible API. Its repository includes model weights, training code, and train, development, and test ...

Capital
Capital

Tundr raises €11.6 million to expand employee benefits platform

Tundr raised €11.6 million in a Series A round to expand its software for managing employee benefits. CDP Venture Capital led the financing through its Corporate Partners I fund, ServiceTech sub-fund and MiSE Co-investment Fund. 3...