Claude Code's source code has been exposed via a map file in its NPM registry, marking one of the most severe open-source security breaches this month. The leak, which earned 27 points and 5 comments on Hacker News, reveals proprietary AI agents and logic that competitors like #3 (GitHub Copilot's internal architecture) have kept under wraps. Security researchers have already identified 12 distinct API keys and 3 hardcoded authentication tokens within the exposed files. While quieter than the chaos of #4, this incident underscores how dependency management failures can outrank malware attacks in real-world impact. The leak is 40% larger than the average npm exposure from 2025, making it a benchmark for industry vulnerability analysis.

Comments on "Claude Code's source code has been leaked via a map file in their NPM registry"
Create a free account or sign in to join the discussion.
Sign in to join the conversation