Connect Clawsmith to your coding agent. Ship products like crazy.Unlimited usage during betaGet API Key โ†’
โ† Back to dashboard
clawsmith.com/signal/claude-code-source-code-npm-leak
๐Ÿ”ฅ HypeUnknowntoolLive

Claude Code 512K-Line Source Code Leaked via npm Source Map

Anthropic accidentally shipped a 59.8MB source map file in @anthropic-ai/claude-code v2.1.88 on npm, exposing 1,900 TypeScript files and 512,000 lines of code. Discovered by @Fried_rice, mirrored across GitHub within hours. Revealed KAIROS autonomous daemon mode, Undercover Mode for stealth OSS contributions, 44 unreleased feature flags, internal model codenames (Capybara, Fennec, Numbat), and a BUDDY virtual pet easter egg. Second Anthropic leak in 5 days after the Mythos CMS incident.

Product Idea from this Signal

A pre-publish scanner that strips source maps, secrets, and internal code from npm packages before they ship to the registry

26142.3k โ–ฒ

Anthropic accidentally shipped 512K lines of Claude Code source code via an npm source map file that was never meant to be public. This happens constantly because .npmignore and package.json files fields are easy to misconfigure. The repo got 100K+ stars in days as people reversed the entire codebase. This tool scans your npm package before publish, catches source maps, leaked environment variables, internal documentation, and accidentally included files, then blocks the publish until you fix it.

SECURITYCLIDEVTOOLNPMOPEN-SOURCE
Competitive40 leadsView Opportunity โ†’

Score Breakdown

X
16,018,899
Reddit
10,006,500
GitHub
111,956
HN
4,900

Frequently Asked Questions