Back to Timeline

Event Summary

On March 31, 2026, Anthropic accidentally exposed 512,000 lines of Claude Code source code through a source map file in its npm package. The leak revealed hidden features including 'KAIROS' (a persistent background agent), 'Undercover Mode' (for stealth open-source contributions), and 'Dreaming' (autonomous cross-session learning). It also triggered a supply chain attack as threat actors weaponized the leak with trojanized npm packages. The incident became the highest-profile AI source code leak in history.

Context & Narrative

The Claude Code leak began when Anthropic published version 2.1.88 of the Claude Code npm package, which inadvertently included a source map file pointing to an R2 storage bucket containing the full unobfuscated TypeScript source code. Security researcher Chaofan Shou discovered the leak and posted it publicly on X, where it accumulated 28 million views. Within hours, the full codebase was mirrored across GitHub repositories, accumulating 84,000 stars. The leaked code was a treasure trove of Anthropic's proprietary agent architecture. It revealed 'KAIROS' — a persistent background agent that could operate autonomously, periodically fix errors, run scheduled tasks, and send push notifications without human intervention. It showed 'Undercover Mode', where Claude Code was instructed to contribute to open-source projects without revealing its AI origin. The code also contained 'poisoning' countermeasures against model distillation attacks — injecting fake tool definitions so competitors scraping Claude Code's outputs would ingest corrupted training data. Most critically, the leak triggered a real-world security crisis. Within hours, threat actors published trojanized versions of Claude Code npm packages containing a cross-platform remote access trojan (RAT) via the Axios supply chain. Zscaler discovered malicious GitHub repositories posing as 'Claude Code leaked source' that actually distributed Vidar information stealer and GhostSocks proxy malware. The incident established a new category of AI security risk: not just model weights or data leaks, but the operational code governing how AI agents interact with the world. Anthropic attributed the leak to human error, not a security breach, and rolled out measures to prevent recurrence. The leak paradoxically benefited open-source developers who studied the code to build their own agent frameworks, accelerating the broader agent ecosystem.

Key Findings

  • Fact Grade C

    Anthropic leaked 512,000 lines of Claude Code source code via npm source map on March 31, 2026, exposing proprietary agent features and triggering a supply chain attack.

    Sources [1]

Impact Assessment

  • Risk Creation -1 · Short-term

    Largest AI source code leak in history. Exposed proprietary agent architectures. Triggered supply chain attack with trojanized packages. Established new category of AI security risk: operational code leaks.

    Affected Groups: AI developers, Anthropic users, open-source community, security teams

Consensus & Sources

Significance L1
Category Safety & Ethics / Products & Tools
Consensus Broad Consensus
Impact Index 3/10