Live
Black Hat USAAI BusinessBlack Hat AsiaAI BusinessPakistan’s peace plan a ‘critical opportunity’ for US-Iran talks ahead of Trump deadlineSCMP Tech (Asia AI)Why Microservices Struggle With AI SystemsHackernoon AIAgentic AI Vision System: Object Segmentation with SAM 3 and QwenPyImageSearchWhy APEX Matters for MoE Coding Models and why it's NOT the same as K quantsReddit r/LocalLLaMAAt least 80 different Microsoft Copilot products have been mapped out by expert, but there may be more than 100 — Microsoft doesn't have a singular list available, so AI consultant mapped out the myriad products - Tom's HardwareGNews AI MicrosoftGoogle Study: AI Benchmarks Use Too Few Raters to Be Reliable - WinBuzzerGNews AI benchmarkNvidia Stock Rises. This Issue Could Hamper Its Next-Generation AI Chips. - Barron'sGNews AI NVIDIABroadcom's CEO Has Line of Sight to $100 Billion in AI Chip Revenue. Is the Stock a Buy? - The Motley FoolGoogle News: AI‘This is 160-million-year-old Jurassic clay’: inside Es Devlin’s bid to reshape AI ethics – through potteryThe Guardian AI‘This is 160-million-year-old Jurassic clay’: inside Es Devlin’s bid to reshape AI ethics – through pottery - The GuardianGNews AI ethicsI gave Claude Code our entire codebase. Our customers noticed. | Al Chen (Galileo)lennysnewsletter.comGoogle DeepMind and Agile Robotics Combine Robotics Platforms - Automation WorldGoogle News: DeepMindBlack Hat USAAI BusinessBlack Hat AsiaAI BusinessPakistan’s peace plan a ‘critical opportunity’ for US-Iran talks ahead of Trump deadlineSCMP Tech (Asia AI)Why Microservices Struggle With AI SystemsHackernoon AIAgentic AI Vision System: Object Segmentation with SAM 3 and QwenPyImageSearchWhy APEX Matters for MoE Coding Models and why it's NOT the same as K quantsReddit r/LocalLLaMAAt least 80 different Microsoft Copilot products have been mapped out by expert, but there may be more than 100 — Microsoft doesn't have a singular list available, so AI consultant mapped out the myriad products - Tom's HardwareGNews AI MicrosoftGoogle Study: AI Benchmarks Use Too Few Raters to Be Reliable - WinBuzzerGNews AI benchmarkNvidia Stock Rises. This Issue Could Hamper Its Next-Generation AI Chips. - Barron'sGNews AI NVIDIABroadcom's CEO Has Line of Sight to $100 Billion in AI Chip Revenue. Is the Stock a Buy? - The Motley FoolGoogle News: AI‘This is 160-million-year-old Jurassic clay’: inside Es Devlin’s bid to reshape AI ethics – through potteryThe Guardian AI‘This is 160-million-year-old Jurassic clay’: inside Es Devlin’s bid to reshape AI ethics – through pottery - The GuardianGNews AI ethicsI gave Claude Code our entire codebase. Our customers noticed. | Al Chen (Galileo)lennysnewsletter.comGoogle DeepMind and Agile Robotics Combine Robotics Platforms - Automation WorldGoogle News: DeepMind
AI NEWS HUBbyEIGENVECTOREigenvector

Claude Code's Source Leaked

Dev.to AIby Yasas BanuMarch 31, 20262 min read3 views
Source Quiz
🧒Explain Like I'm 5Simple language

Hi there, little friend! Let's talk about a silly oopsie!

Imagine your favorite toy robot, Claude. Claude has a secret recipe book inside its head that tells it how to talk and play.

Well, guess what? Someone at Claude's house accidentally left the recipe book open for everyone to see! 😱 It wasn't a bad guy breaking in, just a little mistake, like leaving your lunchbox open.

Now, some smart people saw parts of Claude's secret recipe. They saw new ideas for Claude, like new games it could play.

But don't worry! Claude's brain is still safe, and it can still play with you. It's just like if someone peeked at your secret cookie recipe – they know how to make them, but your cookies are still yummy! It teaches us to be super careful with our secret things. 😊

<h2> 🚨 Alright guys huge deal breaker </h2> <p>‎ </p> <p>🔓 Someone left the door open at Anthropic. And the AI world just walked in.<br> Three days ago, security researcher Chaofan Shou (@ Fried_Rice) noticed something unusual in the npm registry.</p> <p>Tucked inside version 2.1.88 of @anthropic-ai/claude-code was a 57MB file called cli.js.map a source map that acted as a complete decoder ring back to Anthropic's original TypeScript source code.</p> <p>No sophisticated hack. No zero day exploit.<br> Just a single misconfigured build script.</p> <p>What developers found inside 1,900 files:<br> 🧠 <strong>Self-healing memory</strong>: A three-layer architecture built to fight context decay in long AI sessions<br> 📅 <strong>Unreleased model codenames</strong>: "Fennec" (Opus 4.7), "Sonnet

🚨 Alright guys huge deal breaker

🔓 Someone left the door open at Anthropic. And the AI world just walked in. Three days ago, security researcher Chaofan Shou (@ Fried_Rice) noticed something unusual in the npm registry.

Tucked inside version 2.1.88 of @anthropic-ai/claude-code was a 57MB file called cli.js.map a source map that acted as a complete decoder ring back to Anthropic's original TypeScript source code.

No sophisticated hack. No zero day exploit. Just a single misconfigured build script.

What developers found inside 1,900 files: 🧠 Self-healing memory: A three-layer architecture built to fight context decay in long AI sessions 📅 Unreleased model codenames: "Fennec" (Opus 4.7), "Sonnet 4.8," and the mysterious "Capybara" (Claude Mythos) 🤖 Built-in agent swarms: Claude can spawn parallel sub-agents autonomously. This isn't a feature. It's infrastructure. 👻 Ghost contributing: Logic for contributing to open-source repos without explicit AI attribution

Anthropic's response: Human error in release packaging. No model weights compromised. No customer data exposed. The brain is still safe. But the skeleton is now public.

Here's the lesson no one wants to say out loud:

You can spend years and hundreds of millions building a proprietary AI system. And one forgotten line in a .npmignore can make it readable to anyone with a terminal.

Security isn't just about your models. It's about your build pipeline, your CI config, your npm publish script.

The smallest door is still a door.

🔗 Original discovery: Twitter Post - Chaofan Shou 🔥Link to the opensource github repo of claude code I just published: Yasas Banu - Claude Code Repo

Was this article helpful?

Sign in to highlight and annotate this article

AI
Ask AI about this article
Powered by Eigenvector · full article context loaded
Ready

Conversation starters

Ask anything about this article…

Daily AI Digest

Get the top 5 AI stories delivered to your inbox every morning.

More about

claudemodelrelease

Knowledge Map

Knowledge Map
TopicsEntitiesSource
Claude Code…claudemodelreleaseversionopen-sourcefeatureDev.to AI

Connected Articles — Knowledge Graph

This article is connected to other articles through shared AI topics and tags.

Knowledge Graph100 articles · 197 connections
Scroll to zoom · drag to pan · click to open

Discussion

Sign in to join the discussion

No comments yet — be the first to share your thoughts!

More in Releases