2026-03-31
Claude Code source code leaks via npm, exposing secret agent features and raising supply chain concerns
Event Summary
Claude Code source code leaked via npm in 2026, exposing secret agent features and raising AI supply chain security concerns. How a leak revealed what AI coding tools can really do.
Impact Assessment
-
Risk Creation -1 · Short-term
Largest AI source code leak in history. Exposed proprietary agent architectures. Triggered supply chain attack with trojanized packages. Established new category of AI security risk: operational code leaks.
Affected Groups: AI developers, Anthropic users, open-source community, security teams
Consensus & Sources
Significance
L1
Category
Safety & Ethics / Products & Tools
Consensus
Broad Consensus
Impact Index
3/10
-
1
Claude Code source code leaked via npm packaging error. 512,000 lines of TypeScript files exposed.News Report Citation logged Live source
-
2
Anthropic confirms Claude Code source code inadvertently released due to human error.News Report Citation logged Live source
-
3
Threat actors weaponizing Claude Code leak with trojanized packages distributing Vidar and GhostSocks.News Report Citation logged Live source