
Anthropic, a U.S.-based artificial intelligence company known for its Claude family of AI models, inadvertently exposed the full source code of its closed-source Claude Code tool after a software release mistakenly included internal files, the company confirmed.
The incident occurred on March 31, 2026, when Anthropic briefly published Claude Code version 2.1.88 to the npm registry, a widely used platform for distributing developer tools. The release contained a 60 MB source map file, cli.js.map, which allowed the reconstruction of the application’s complete source code.
Anthropic stated that the exposure was caused by a release packaging error stemming from human oversight and not a cyberattack. The company confirmed that no customer data, credentials, or sensitive information were exposed during the incident and said additional safeguards are being implemented to prevent a recurrence.
The leaked file included embedded source content that enabled the recovery of approximately 1,900 files and roughly 500,000 lines of code. The exposed codebase covered core components of the Claude Code command-line tool, including internal APIs, telemetry systems, encryption-related functions, and communication protocols.
Claude Code, which has remained proprietary despite Anthropic’s broader support for open-source initiatives, is designed as a developer-focused tool for interacting with AI models through a command-line interface. The unintended disclosure provided visibility into features that had not yet been publicly announced.
Among the capabilities identified in the code are experimental modes such as “Proactive mode,” which enables continuous autonomous coding, and “Dream mode,” designed to allow the system to process ideas and refine solutions in the background.
The exposed code quickly circulated across developer platforms, including GitHub, where it was replicated and analyzed. Anthropic has initiated takedown efforts using copyright enforcement mechanisms to limit further distribution.
The issue highlights the risks associated with source map files, which are commonly used during development to map compiled code back to its original human-readable form. When such files include embedded source content and are published in production releases, they can inadvertently reveal the entire underlying codebase.
This marks at least the second instance of a similar exposure involving Claude Code, following a prior incident in 2025 that also involved unintended publication of source maps.
Separately, Anthropic is investigating a reported issue affecting Claude Code usage limits. Users across paid plans have reported that usage quotas are being exhausted significantly faster than expected during normal interactions. The company acknowledged the issue and said it is actively working on a fix, describing it as a high-priority investigation.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543