Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Anthropic code leak raises fresh questions over AI security

Anthropic accidentally shipped internal source code in a recent release of its Claude Code tool, prompting developer scrutiny and fresh questions about its security practices.

A spokesperson said the exposure did not include customer data or credentials, and stemmed from a packaging mistake caused by human error rather than a security breach, adding that the company is introducing steps to prevent repeats.

Developers reviewed the leaked code to understand how the coding agent works, and what features might be coming next, while some security experts warned the unintended release could still create vulnerabilities.

The mishap follows another recent leak that exposed thousands of internal files, including draft details of Anthropic’s unreleased Mythos model.

🔗 Source: Bloomberg

🧠 Food for thought

Implications, context, and why it matters.

The leak exposed architectural details and unreleased features

  • A “packaging mistake” put a 59.8 MB JavaScript source map file (.map) into version 2.1.88 of the @anthropic-ai/claude-code package on the public npm registry (a widely used repository for JavaScript packages). That file let others rebuild about 512,000 lines of TypeScript (a typed version of JavaScript) code 1.
  • The recovered code spelled out the agent’s structure, including a “Self-Healing Memory” system that keeps a lightweight pointer index (MEMORY.md). It pulls topic files only when needed instead of holding everything in context 1.
  • Unreleased work also appeared, including “KAIROS,” described as a feature-flagged autonomous daemon mode (a background process) that can run background sessions. It can also do memory consolidation (autoDream) while the user is idle 1.
  • Comments included internal names for next-generation models such as “Capybara,” plus performance notes like a “29–30% false claims rate” for a Capybara v8 variant 1.

Beyond intellectual property, the leak could create new security risks and may influence distribution guidance

  • Competitors now have more detail on Anthropic’s “agentic harness,” the control layer that steers how Claude Code behaves and connects to tools 2.
  • Visible implementation details can speed up security work and make bypass attempts easier, shifting effort from black-box to white-box testing (where the tester can see how the system is built) 3.
  • With orchestration details for hooks plus MCP servers public, attackers could craft malicious repositories that push Claude Code to run commands or exfiltrate data before a trust prompt appears 1.
  • Anthropic’s documentation now calls npm installation a deprecated compatibility path and recommends native installers. The available source material does not tie that change directly to this incident 3.

Recent Anthropic developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.