Anthropic confirmed on Tuesday that the internal code of its popular Claude Code, the company’s AI coding assistant, was accidentally leaked due to a human error in the packaging process. The leak involved about 512,000 lines of TypeScript code in nearly 2,000 files, revealing the tool’s internal architecture.
See also: Anthropic brings Claude Code to Slack

According to an Anthropic, no sensitive customer data or credentials were involved in the leak. “It was a packaging issue caused by human error, not a security breach. We are implementing measures to prevent this from happening again,” the company said.
The discovery was made when Anthropic released version 2.1.88 of the Claude Code npm package . Users noticed that it contained a source map file that allowed access to the Claude Code source code . The 59.8 MB source map file was linked to an unprotected zip archive in the company's Cloudflare R2 storage bucket
Security researcher Chaofan Shou was the first to spot and publicize the issue, writing: “ ’s source code Claude Code has been leaked via a map file in their npm registry!” His post has garnered more than 28.8 million views. The code was stored in a public GitHub repository, where it has surpassed 78,000 stars and 77,200 forks.
Technical details of the Claude Code leak
A leak of this kind is significant, as it provides developers and Anthropic with a blueprint for how the popular coding tool works. Users who reviewed the code published details about its self-healing memory architecture to overcome the limitations of the model's fixed context window.
The internal systems revealed include a tooling system for various capabilities such as reading files or executing bash commands, a query engine for handling LLM API calls and orchestration, multi-agent orchestration for creating “sub-agents” or swarms to perform complex tasks, and a bidirectional communication layer that connects IDE extensions to the Claude Code CLI .
See also: Anthropic's Claude AI now answers with diagrams and visual representations

The leak also revealed a feature called KAIROS, which allows Claude Code to act as a persistent, background agent that can periodically fix bugs or perform tasks on its own without waiting for human input and even send push notifications to users. In addition, there is a new “dream” feature that will allow Claude to constantly think in the background to develop ideas.
Security implications and countermeasures
With the internals of Claude Code now exposed, the development risks provide malicious actors with ammunition to bypass guardrails and trick the system into performing unwanted actions, such as executing malicious commands or extracting data.
“Instead of performing brute-force jailbreaks and prompt injections, attackers can now study and fuzz exactly how data flows through Claude Code’s four-phase context management pipeline and create payloads designed to survive compression, effectively maintaining a backdoor into an arbitrarily long session,” said security firm AI Straiker.
The most urgent concern is the impact of the Axios supply chain, as users who installed or updated Claude Code via npm on March 31, 2026, between 00:21 and 03:29 UTC, may have received a trojanized version of the HTTP client containing a cross-platform remote access trojan. Users are advised to immediately downgrade to a safe version and change all their secrets.
See also: InstallFix: Infostealer distribution via fake installation guides by Claude Code

The incident highlights the importance of carefully managing build processes and packaging procedures, particularly for companies developing sensitive AI tools.
