<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Claude-Code on Token Times</title><link>https://tokentimes.net/tags/claude-code/</link><description>Recent content in Claude-Code on Token Times</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Token Times</copyright><lastBuildDate>Thu, 02 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://tokentimes.net/tags/claude-code/index.xml" rel="self" type="application/rss+xml"/><item><title>Accidental Leak Exposes Claude Code's Source Code and Internal Secrets</title><link>https://tokentimes.net/posts/2026-04-02-claude-code-leak/</link><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><guid>https://tokentimes.net/posts/2026-04-02-claude-code-leak/</guid><description>
&lt;p&gt;&lt;figure&gt;
&lt;picture&gt;
&lt;img
loading="lazy"
decoding="async"
alt="Accidental Leak Exposes Claude Code&amp;amp;amp;rsquo;s Source Code and Internal Secrets"
class="image_figure image_internal image_unprocessed"
src="https://tokentimes.net/images/2026-04-02/claude-code-leak.png"
/&gt;
&lt;/picture&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;A human packaging error accidentally included nearly 60 megabytes of source map files in Claude Code version 2.1.88 via npm, exposing around 500,000 lines of original TypeScript code that included the AI&amp;rsquo;s internal prompts, orchestration logic, and a controversial &amp;ldquo;Undercover Mode&amp;rdquo;.&lt;/p&gt;
&lt;h2 id="context"&gt;Context&lt;/h2&gt;
&lt;p&gt;On March 31, 2026, Anthropic published what was expected to be a simple routine update (version 2.1.88) for the Claude Code npm package—their cutting-edge command-line interface (CLI) assistant agent targeting software developers. However, a configuration misstep during the deployment sent a 59.8 MB &lt;code&gt;.map&lt;/code&gt; file straight into the package registry. These Source Map files allowed developers and researchers to reverse-engineer the transpiled JavaScript and completely access approximately 500,000 lines of the application&amp;rsquo;s core un-obfuscated TypeScript source code. Anthropic quickly confirmed the oversight was caused by a &amp;ldquo;release packaging human error,&amp;rdquo; instantly dismissing rumors of malicious network breaches or an intentional pivot to Open Source distribution.&lt;/p&gt;</description></item></channel></rss>