512,000 lines of leaked AI agent source code, three mapped attack paths, and the audit security leaders need now

Key summary
@anthropic-ai/claude-code v2.1.88 included a 59.8 MB source map that exposed 512,000 lines of unobfuscated TypeScript across 1,906 files.
The readable source contained the permission model, security validators, feature flags, and references to upcoming models.
Researcher Chaofan Shou posted the discovery on X at about 04:23 UTC; Anthropic said the exposure was a human packaging error and that no customer data or model weights were involved.
Malicious versions of the axios npm package went live hours earlier; teams that installed Claude Code via npm between 00:21 and 03:29 UTC on March 31 may have pulled both the exposed source and the axios malware.
Anthropic filed takedowns that removed more than 8,000 copies from GitHub but later limited/retracted takedowns except for one repo and GitHub restored affected forks; Gartner urged leaders to rethink vendor evaluation and said Claude Code is the most discussed AI coding agent among its clients, and this follows a CMS misconfiguration five days earlier that exposed nearly 3,000 unpublished internal assets.
