Claude Code source leak exposes 513,000 lines after npm publishing error

Claude Code source leak exposes 513,000 lines after npm publishing error

N
News Editor
2026-07-28 06:43:56
Anthropic’s Claude Code CLI tool accidentally exposed about 513,000 lines of TypeScript source code on March 31 after a publishing configuration mistake, according to a Techub News report citing Cryptobriefing. The issue stemmed from an npm release that incorrectly included source map files that were not meant to be public, exposing nearly 2,000 internal files. The report said Anthropic’s follow-up DMCA takedown request also hit roughly 8,100 unrelated GitHub repositories by mistake. At the same time, malicious actors have started setting up fake repositories to distribute malware, attempting to lure developers into cloning infected code. Anthropic said the incident was caused by human error rather than a security flaw. The company also said no sensitive user data or credentials were exposed in the leak. The episode has turned attention to supply-chain risk for developers using public code hosting and package distribution channels, especially when attackers move quickly to exploit confusion around a widely discussed tooling incident.
AnthropicClaude Codesource leaknpmmalwareGitHubdeveloper security

Anthropic’s Claude Code CLI tool accidentally exposed about 513,000 lines of TypeScript source code on March 31 after a publishing configuration error, according to Techub News, which cited Cryptobriefing.

The problem came from an npm release that mistakenly included source map files that were not supposed to be public. That exposed nearly 2,000 internal files.

The report said Anthropic also made a mistake in its DMCA takedown effort, with roughly 8,100 unrelated GitHub repositories affected.

Malicious actors are now creating fake repositories to spread malware and trick developers into cloning infected code.

Anthropic said the incident was the result of human error, not a security vulnerability. The company added that no sensitive user data or credentials were exposed.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.