Anthropic’s Claude Code Source Leaked
In what is being called one of the most significant accidental disclosures in recent Silicon Valley history, Anthropic has unintentionally exposed the complete source code for its flagship developer tool, Claude Code (via Venture Beat).
The leak, which occurred earlier today, has given the global developer community an unprecedented look at the inner workings of one of the world’s most advanced AI coding agents.
The security slip-up traces back to the release of version 2.1.88 of the @anthropic-ai/claude-code package on the public npm registry. Due to a configuration error in the build pipeline, the update included a 60MB JavaScript source map file. While these files are standard for internal debugging, this specific map file contained references that allowed researchers to reconstruct the original TypeScript source code.
Security researcher Chaofan Shou was among the first to flag the exposure. By the time Anthropic moved to pull the package, the damage was done. The codebase, comprising roughly 1,900 files and over 512,000 lines of code, was quickly mirrored on GitHub, where it gained tens of thousands of stars and forks in a matter of hours.
Beyond just a peek at the current version, the leaked files contain references to several unreleased projects that hint at Anthropic’s future strategy. Most notable is a feature dubbed “KAIROS.” This appears to be a persistent “daemon mode” where Claude Code can run in the background, observing a developer’s workflow and proactively suggesting fixes or performing tasks without waiting for a direct prompt.
Another significant discovery is “Ultraplan,” a high-level orchestration system that reportedly offloads complex planning to a remote Cloud Container Runtime.
For a company with an annualized revenue run rate nearing $19 billion, such a public error is a humbling reminder of the risks inherent in rapid software deployment. While Anthropic has confirmed that no user data or core model weights were compromised, the leak is a goldmine for its competitors.
Want to see more of our stories on Google?
P.S. Want to keep this site truly independent? Support us by buying us a beer, treating us to a coffee, or shopping through Amazon here. Links in this post are affiliate links, so we earn a tiny commission at no charge to you. Thanks for supporting independent Canadian media!
