Skip to main content

Share story

AI Security

Anthropic's Claude Code Source Code Exposed Through Map File in NPM Package

Source code for Anthropic's Claude Code, the company's terminal-based AI coding assistant, has been inadvertently exposed through a JavaScript source map file included in the tool's published NPM package, according to a post surfaced on Hacker News on Tuesday. Source map files are typically used during development to link minified or compiled JavaScript back to original source code for debugging purposes. When accidentally included in a production NPM release, they expose the underlying unminified source, including internal logic, comments, and implementation details that the publisher may have intended to keep private. Claude Code is Anthropic's command-line tool for agentic software development, allowing engineers to delegate coding tasks, navigate codebases, and run automated code modifications. The tool has gained significant adoption among professional developers since its release and is positioned as a commercial product with a paid subscription tier. The exposure does not constitute a security breach in the traditional sense. no customer data or credentials appear to have been leaked. but it gives competitors and researchers access to Anthropic's proprietary implementation choices for the tool, which the company has not open-sourced. Source map leaks in production packages are a known category of accidental disclosure. Companies typically prevent them by configuring their build toolchain to strip map files before publishing to NPM. The issue can be remedied by releasing a new version without the map file, though previously published versions remain accessible. Anthropic had not issued a public statement acknowledging the disclosure at time of publication. The company did not respond to requests for comment.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Infrastructure
Security Infrastructure

Two unpatched NetScaler flaws reportedly exploited in attacks

Security firm watchTowr says attackers have exploited two previously undisclosed flaws that could allow remote code execution on Citrix NetScaler appliances. The firm said it identified the flaws during forensic investigations and...

Products Capital
Products Capital

Numeral raises $100M for sales tax automation

Numeral raised a $100M Series C led by Insight Partners, FinTech Global reported. Its AI-powered platform automates sales tax compliance workflows in over 90 countries. The financing adds capital to a business serving companies t...

Capital Products
Capital Products

HIFI raises $37M for stablecoin payment infrastructure

HIFI raised a $37M Series A led by Left Lane Capital, The Block reported. The New York City company provides software interfaces for stablecoin payments and settlements, giving businesses a way to connect those transactions to the...

Infrastructure Capital
Infrastructure Capital

PicoJool raises $27.5M for AI data center interconnects

PicoJool raised a $27.5M Series A led by Socratic Partners, SiliconANGLE reported. The startup is developing interconnects for AI data centers based on vertical cavity surface emitting lasers. Former Intel chief executive Pat Gel...

Robotics Products
Robotics Products

Volkswagen weighs exit from robotaxi business Moia

Volkswagen intends to explore options for exiting its Moia robotaxi business by the end of 2026, including a sale to investors or liquidation, Heise reported, citing Wirtschaftswoche's account of an internal strategy paper. The re...