On 31 March 2026, Anthropic accidentally published a 59.8 MB unminified JavaScript source map inside the public npm package @anthropic-ai/claude-code version 2.1.88, exposing roughly 513,000 lines of the tool’s TypeScript source across 1,906 files. The leak, discovered and publicized by an outside security researcher, revealed internal codenames and unshipped features before the codebase was mirrored to GitHub and forked thousands of times within hours. Anthropic attributed the leak to human error during release packaging combined with a build-tool bug that generated the debug file by default, and said no customer data, credentials, backend infrastructure details, or model weights were exposed.