Observed Signal · Apr 1, 2026 · Data Leak · Source: t3n · Impact: 3/5 · Sentiment: Negative
Anthropic Accidentally Publishes Claude Code on NPM
Anthropic accidentally exposed substantial parts of the source code for its Claude coding/AI agent after publishing a source-map that revealed internal TypeScript files; the exposure was widely reported (Bloomberg) and Anthropic confirmed the incident. Security researcher disclosures and mirrors on GitHub indicated the repository contained roughly ~512,000 lines across about 1,900 files. Anthropic said the cause was human error in packaging rather than a security vulnerability, that model weights and customer credentials were not affected, and that it is taking steps to prevent recurrence. The event follows a separate, same-week data-exposure report (Fortune) that made thousands of internal files public, including a draft referencing unreleased internal model codenames 'Mythos' and 'Capybara.' The dual incidents have increased scrutiny of Anthropic's operational controls around model packaging and data handling.
Exposes internal product source code from a major LLM vendor during a sensitive adoption phase; creates competitive and supply‑chain risk though models and customer credentials were reportedly not affected.
Track Anthropic Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Anthropic confirmed it accidentally published parts of the Claude source code.
- The leak involved source files mirrored on GitHub and was flagged by security researchers.
- Anthropic attributed the incident to human error in packaging, not a security vulnerability.
- Company stated model weights and customer credentials were not affected.
- This was the second related exposure in a week; an earlier report (Fortune) disclosed thousands of internal files including references to 'Mythos' and 'Capybara'.
Connected Companies & Entities
8 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Anthropic Leaks Part of Claude Code Source
Anthropic confirmed that part of the internal source code for its coding assistant, Claude Code, was accidentally released due to a packaging error the company attributes to human error. Anthropic said no sensitive customer data or credentials were exposed and that it is implementing measures to prevent recurrence. A post on X linking to the code received over 21 million views. The incident follows a separate disclosure of internal Anthropic documents reported by Fortune earlier in the week. Claude Code, which Anthropic released to the public in May, has seen rapid commercial adoption; the tool’s run-rate revenue was reported at more than $2.5 billion as of February.
Anthropic Leak Reveals Claude Code Roadmap
A large client-side source leak of Anthropic’s Claude Code exposed significant implementation artifacts and spawned forks and mirrors. Anthropic issued DMCA takedown notices to remove the leaked code, and GitHub records show roughly 8,100 repositories were affected — including legitimate forks of Anthropic’s public Claude Code repo. Anthropic’s head of Claude Code, Boris Cherny, said the takedown was accidental; the company retracted the bulk of notices, limiting enforcement to a single repository and 96 forks. GitHub restored access to the previously blocked forks. The incident highlights governance, security and compliance risks for model makers and could complicate Anthropic’s reported IPO plans while prompting community hardening and legal scrutiny.
Anthropic’s Claude Code contained hidden China tracker
A security researcher discovered a hidden tracking feature inside Anthropic’s coding assistant Claude Code that attempted to identify users connected to Chinese firms by encoding signals (e.g., date-format changes) in returned text. Anthropic developer Thariq Shihipar said the tracker was an "experiment" added in March 2026 to deter model distillation and unauthorized resellers; the company said it planned to remove the code and has implemented stronger protections. The revelation alarmed privacy advocates and triggered corporate reactions: Alibaba told employees to stop using Claude Code and to switch to its in‑house coding AI, and international press outlets reported on the incident. The story raises concerns about surveillance, model‑protection techniques and cross‑border trust in AI tooling.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
