Anthropic confirmed on Tuesday that a portion of the internal source code for its AI code assistant, Claude Code, had been leaked. A company spokesperson stated that the leak did not involve sensitive customer data or credential information, and was attributed to a human error in the release packaging process, not a security breach. Anthropic is taking measures to prevent similar incidents from recurring. According to reports, the leak originated from source mapping files inadvertently included in an npm package, containing over 510,000 lines of TypeScript code and more than 40 utility modules, exposing unreleased features and internal architecture. The leak did not affect the core model weights but has raised concerns about software supply chain security.
