Close Menu
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
What's Hot

Claude Code CLI Exposed via npm Source Map Error – Bitcoin News

April 1, 2026

Anthropic Data Shows Australia Punches Above Weight in AI Adoption

March 31, 2026

Trump’s $200B Iran war ask raises risk-off pressure on crypto markets

March 31, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
CatchTheBullCatchTheBull
Bitcoin

Claude Code CLI Exposed via npm Source Map Error – Bitcoin News

By WebDeskApril 1, 20264 Mins Read
Claude Code CLI Exposed via npm Source Map Error – Bitcoin News
Share
Facebook Twitter LinkedIn Pinterest Email

Claude Code npm Leak Reveals Unreleased Features Including KAIROS, BUDDY, and Agent Swarms

The company confirmed the incident on March 31, 2026, speaking with Venture Beat, attributing it to human error in the release packaging process. Version 2.1.88 of @anthropic-ai/claude-code shipped with a 59.8 MB Javascript source map file. Basically a debugging artifact that mapped minified production code back to the original Typescript, which pointed directly to a publicly accessible zip archive sitting on Anthropic‘s own Cloudflare R2 storage bucket.

Nobody had to hack anything. The file was just there.

Security researcher Chaofan Shou, an intern at blockchain security firm Fuzzland, spotted the issue and posted the direct bucket link on X. Within hours, mirrored repositories appeared on Github, some accumulating tens of thousands of stars before Anthropic’s DMCA takedowns hit. Community members had already begun stripping telemetry, flipping hidden feature flags, and drafting clean-room reimplementations in Python and Rust to sidestep copyright concerns.

The root cause was straightforward: Bun’s bundler generates source maps by default, and no build step excluded or disabled the debug artifact before publishing. A missing entry in .npmignore or the files field in package.json would have prevented the whole thing.

What developers found inside was detailed. The ~1,900 Typescript files covered tool execution logic, permission schemas, memory systems, telemetry, system prompts, and feature flags — a full engineering view of how Anthropic builds a production-grade agentic coding tool. Telemetry scans prompts for profanity as a frustration signal but does not log full user conversations or code. An “undercover mode” instructs the AI to remove references to internal codenames and project details from git commits and pull requests.

Several unreleased features sat behind flags. KAIROS is described as an always-on background daemon that watches files, logs events, and runs a “dreaming” memory-consolidation process during idle time. BUDDY is a terminal pet with 18 species — including capybara — carrying stats like DEBUGGING, PATIENCE, and CHAOS. COORDINATOR MODE lets a single agent spawn and manage parallel worker agents. ULTRAPLAN schedules 10- to 30-minute remote multi-agent planning sessions.

Anthropic told Venture Beat the incident involved no sensitive customer data, no credentials, and no compromise of model weights or inference infrastructure. “This was a release packaging issue caused by human error,” the company said, adding that it is rolling out measures to prevent a repeat.

Those measures may need to move quickly. This is the second time the same mistake has happened. A nearly identical source-map leak occurred with an earlier version of Claude Code in February 2025.

The March 31 incident also landed alongside a separate npm supply-chain attack on the axios package, active between 00:21 and 03:29 UTC. Developers who installed or updated Claude Code via npm during that window are advised to audit their dependencies and rotate credentials. Anthropic recommends its native installer over npm going forward.

Context matters here. Five days earlier, on March 26, a CMS misconfiguration at Anthropic exposed roughly 3,000 internal files covering details on the unreleased “Claude Mythos” model, also attributed to human error. Two significant accidental disclosures in less than a week raises questions about release hygiene at a company whose tools are actively used to write and ship code at scale.

The leaked source code remains available in archived and mirrored forms despite active takedown enforcement. Anthropic has not published a broader post-mortem or public statement beyond its comment to Venture Beat.

No user data was exposed. The core Claude models are unaffected. The blueprint for building a competitor to Claude Code, however, is now considerably easier to assemble.

FAQ 🔎

  • Q: Was the Claude Code source code leak a hack? No — Anthropic confirmed the exposure was a packaging error, not a security breach or unauthorized access.
  • Q: What was actually exposed in the Anthropic npm leak? Approximately 512,000 lines of TypeScript covering the Claude Code CLI, including telemetry, feature flags, hidden features, and agent architecture — not model weights or customer data.
  • Q: Is my data at risk from the Claude Code npm incident? Anthropic says no user data or credentials were exposed; developers who installed via npm during the concurrent axios supply-chain attack window should audit dependencies and rotate credentials.
  • Q: Has Anthropic leaked source code before? Yes — a nearly identical source-map leak involving an earlier Claude Code version occurred in February 2025, making this the second such incident in roughly 13 months.

Credit: Source link

Previous ArticleAnthropic Data Shows Australia Punches Above Weight in AI Adoption

Related Posts

Trump’s $200B Iran war ask raises risk-off pressure on crypto markets

March 31, 2026

Crypto Market First Major Outflow In 5 Weeks – Here’s How Bitcoin And Ethereum Performed

March 31, 2026

Satoshi’s 2010 Quantum Response Is Getting A 2026 Stress Test As Google Warns Timeline May Be Closer Than Expected

March 31, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Claude Code CLI Exposed via npm Source Map Error – Bitcoin News

April 1, 2026

Anthropic Data Shows Australia Punches Above Weight in AI Adoption

March 31, 2026

Trump’s $200B Iran war ask raises risk-off pressure on crypto markets

March 31, 2026

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

Advertisement Banner

Welcome to CatchTheBull, your trusted source for the latest Crypto News and Airdrops. We bring you real-time updates, expert insights, and opportunities to stay ahead in the crypto world. Discover trending projects, market analyses, and airdrop details all in one place.

Join us on this journey to navigate the ever-evolving blockchain universe!

Facebook X (Twitter) Instagram YouTube
Top Insights

Playnance Expands On-Chain With Sports and Esports Push Backed by $GCOIN – Crypto News Flash

BNB Chain Extends Zero-Fee Stablecoin Transfers Through April 30

10 Best AI Trading Bot Crypto Platforms in 2026 (Ultimate Guide)

Get Informed

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

© 2026 CatchTheBull. All Rights Are Reserved.
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$67,604.00-0.41%
  • ethereumEthereum(ETH)$2,087.200.74%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$614.60-0.26%
  • rippleXRP(XRP)$1.33-0.27%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$82.58-1.47%
  • tronTRON(TRX)$0.314412-1.61%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.49%
  • dogecoinDogecoin(DOGE)$0.091681-0.48%
  • USDSUSDS(USDS)$1.000.02%
  • whitebitWhiteBIT Coin(WBT)$51.90-0.59%
  • leo-tokenLEO Token(LEO)$10.022.83%
  • bitcoin-cashBitcoin Cash(BCH)$461.38-0.88%
  • cardanoCardano(ADA)$0.242170-2.47%
  • HyperliquidHyperliquid(HYPE)$36.19-3.31%
  • chainlinkChainlink(LINK)$8.75-0.29%
  • moneroMonero(XMR)$331.701.27%
  • Ethena USDeEthena USDe(USDE)$1.00-0.04%
  • CantonCanton(CC)$0.147405-1.03%
  • stellarStellar(XLM)$0.167527-1.66%
  • daiDai(DAI)$1.000.01%
  • USD1USD1(USD1)$1.000.01%
  • litecoinLitecoin(LTC)$53.84-0.07%
  • MemeCoreMemeCore(M)$2.341.39%
  • zcashZcash(ZEC)$244.555.24%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.01%
  • RainRain(RAIN)$0.0081285.66%
  • avalanche-2Avalanche(AVAX)$8.88-1.70%
  • hedera-hashgraphHedera(HBAR)$0.0882370.50%
  • shiba-inuShiba Inu(SHIB)$0.000006-1.03%
  • suiSui(SUI)$0.87-0.80%
  • the-open-networkToncoin(TON)$1.22-1.66%
  • crypto-com-chainCronos(CRO)$0.0705060.03%
  • BittensorBittensor(TAO)$303.20-3.24%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.098309-1.39%
  • Circle USYCCircle USYC(USYC)$1.120.01%
  • tether-goldTether Gold(XAUT)$4,653.961.83%
  • pax-goldPAX Gold(PAXG)$4,669.942.03%
  • mantleMantle(MNT)$0.690.08%
  • uniswapUniswap(UNI)$3.54-0.44%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • polkadotPolkadot(DOT)$1.25-0.69%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • okbOKB(OKB)$83.53-1.37%
  • Falcon USDFalcon USD(USDF)$1.00-0.02%
  • Pi NetworkPi Network(PI)$0.174556-0.63%
  • SkySky(SKY)$0.074757-4.85%
  • AsterAster(ASTER)$0.67-2.06%
  • HTX DAOHTX DAO(HTX)$0.000002-1.46%