Particle.news

Anthropic Accidentally Publishes Claude Code Source on NPM

The disclosure gives rivals a look at the tool’s design, heightening competitive pressure.

Overview

  • Anthropic confirmed it unintentionally shipped internal source code for its coding assistant Claude Code in a public NPM release.
  • The release included a source-map file that exposed more than 500,000 lines of code across nearly 2,000 files, making the codebase readable.
  • Security researcher Chaofan Shou found the package and posted it on X, after which a snapshot of the code appeared on GitHub.
  • The company said the leak did not include model code or customer credentials and blamed a packaging error caused by human mistake, with new safeguards now underway.
  • Claude Code has become widely used by developers, so public copies of the code raise trust and competitive risks for Anthropic as it navigates recent political scrutiny.