Three days ago some dude named Chaofan Shou noticed something nobody at Anthropic apparently bothered to check – they shipped a source map file (
) in their public npm package
v2.1.88. For those who don't know what that means: you can fully reconstruct the original TypeScript source from it. Every. Single. Line.The numbers:
Code:
cli.js.mapCode:
@anthropic-ai/claude-code- 512,000+ lines of code
- 1,906 files
- Sitting in npm for 13 MONTHS before anyone noticed
What's in it? Glad you asked:
Full internal API architecture & comms protocolsCode:[+]
Telemetry + encryption internalsCode:[+]
Internal model naming conventions + memory architectureCode:[+]
AI roadmap documents (yes, FUTURE MODELS)Code:[+]
A literal hidden Tamagotchi pet easter egg buried in prod code lmaoCode:[+]
They've already fired off 8,000+ DMCA takedowns on GitHub forks. The original X post hit 28M views before they started nuking everything. Wayback Machine copies are floating around if you know where to look.
For the record: no model weights, no user data, no API keys were leaked. This is purely architectural/code intel. But for anyone building competing products or doing security research – this is a goldmine.
Anthropic PR is in full damage control mode right now. Their statement basically amounts to "nothing important to see here" while their legal team burns overtime.
Not ratedThis leak has not been rated yet, be careful when downloading.

![[Image: giphy.gif]](https://patched.to/pbb-proxy/UUNCQ0JeTUoJUlUMAFQXUg9HCk4WU1ZYHF4EVA9RGRMIGW8BXQ8yMQcCfCIoVndfI08Gc2JadmFfQC5nV0hXLV5AeWRgVzsyXQR.MgkOXW0KXy9gQF5YWAJAAkowRWwLYwN5Z3dSOzY.W1IhUFd0Y19HAFlqXFpYBlsDdl9eVzJjUW9dXQIDMjVaaFYwXGNCSV01dgh.c1lVRA4DP0lvKkNeQRxWDRINHRlWDAc-/giphy.gif?t=1771681490)

