On March 31, 2026, Anthropic accidentally published an unobfuscated JavaScript source map inside the public npm package for its Claude Code coding agent, exposing roughly 513,000 lines of proprietary TypeScript across nearly 2,000 files, including the tool’s agent orchestration, memory, and permission systems. A security researcher’s post about the leak drew tens of millions of views before Anthropic could pull the package, and the code was mirrored to GitHub and forked tens of thousands of times within hours. Anthropic characterized it as a packaging error rather than a security breach and issued DMCA takedowns, but threat actors subsequently distributed trojanized copies of the leaked code bundled with malware.