On March 31, 2026, the full source code of Anthropic's Claude Code CLI was leaked via a
.mapfile exposed in their npm registry.
Chaofan Shou (@Fried_rice) discovered the leak and posted it publicly:
"Claude code source code has been leaked via a map file in their npm registry!"
The source map file in the published npm package contained a reference to the full, unobfuscated TypeScript source, which was downloadable as a zip archive from Anthropic's R2 storage bucket.
- Bun v1.3+ (the project's runtime)
- Node.js v18+ (for npm package installation)
- An Anthropic API key (set as
ANTHROPIC_API_KEYenvironment variable)
# 1. Install Bun (if not already installed)
curl -fsSL https://bun.sh/install | bash
source ~/.bash_profile # or restart your terminal
# 2. Install dependencies
npm install --legacy-peer-deps
# 3. Run Claude Code
bun run start
# Or with arguments:
bun run start -- --help
bun run start -- --version
bun run start -- -p "Hello Claude"