• My Feed
  • Home
  • What's Important
  • Media & Entertainment
Search

Stay Curious. Stay Wanture.

© 2026 Wanture. All rights reserved.

  • Terms of Use
  • Privacy Policy
Tech/Software
Anthropic leak reveals Opus 4.7, Sonnet 4.8 in npm 2.1.88

31 March 2026

—

News

Rachel Stein

On March 30 and 31, 2025, Anthropic unintentionally exposed over 512,000 lines of TypeScript code from its Claude Code AI model through an npm source map file, a supply chain misstep that offers a rare window into the company's roadmap while underscoring a vulnerability that could ripple across any organization publishing JavaScript packages.

Why it matters: The exposure reveals previously undisclosed models (Opus 4.7, Sonnet 4.8, and a prototype named Capybara) alongside internal features such as a stealth "Cover Mode," a long term memory system called KAIROS, and even a virtual pet named BUDDY. More broadly, it highlights a systemic weakness in the software supply chain at a moment when credential leaks are accelerating at an unprecedented rate.

What they're saying: Anthropic has not issued a public statement. Industry analysts, however, note that the leak arrived during a broader surge in credential exposure across public code. GitGuardian's 5th edition State of Secrets Sprawl report, released on March 17, 2025, documented 28.65 million new hardcoded secrets in public GitHub commits during 2024 and an 81 percent year over year increase in AI service credential leaks.

Source map files translate minified JavaScript back to original source code, enabling debugging. When published publicly, they can be reverse engineered to reconstruct the original codebase.

Technical details of the exposure: The npm package version 2.1.88 included a .map file weighing 59.8 MB and covering roughly 1,900 files. Researchers extracted approximately 512,000 lines of TypeScript, revealing internal modules such as "Cover Mode" for stealth code contribution, the long term memory system KAIROS, a virtual pet named BUDDY, and a profanity based frustration tracker designed to gauge developer sentiment.

The pattern beneath the numbers: GitGuardian data shows commits co-authored by Claude Code exhibited a 3.2 percent secret leak rate, more than double the 1.5 percent baseline for all public commits. With public GitHub activity reaching 1.94 billion commits in 2024, a 43 percent year over year rise, the scale of the supply chain risk is no longer theoretical. It is structural.

Comparison with other major tech leaks: The 2024 Google Search documentation leak disclosed 350,000 lines of indexing code, while the Claude leak reveals 512,000 lines of active model logic and future model references, making the latter broader in scope and more directly tied to AI product roadmaps.

What's next: Experts warn that internal repositories are approximately six times more likely to contain hardcoded secrets, and 28 percent of leaks now originate from collaboration tools such as Slack, Jira, and Confluence. Moreover, 64 percent of valid secrets detected in 2022 remained active when re-tested in January 2025, indicating a persistent remediation gap that organizations have yet to close.

Recommended security measures for AI labs:

  1. Implement automated scanning of npm packages for accidental source map inclusion before publishing.
  2. Adopt secret management tools that rotate credentials on each commit.
  3. Enforce strict code review policies that flag hardcoded keys in both public and private repositories.
  4. Conduct regular penetration tests of the software supply chain, focusing on third party dependencies.
  5. Provide developer training on secure packaging practices and the risks of source map exposure.
  6. Integrate real time alerts for anomalous commit patterns using services like GitGuardian.
  7. Maintain an incident response playbook specific to supply chain breaches.

For a deeper look at Anthropic's model roadmap, see our earlier coverage of Claude Opus 4.5 for autonomous coding. The Claude Code leak underscores the urgent need for robust software supply chain security as AI development accelerates and the stakes of accidental exposure continue to rise.

banner

What is this about?

  • News/
  • Rachel Stein/
  • Tech/
  • Software

Feed

    Button AI Assistant Debuts, Offering Screen‑Free Voice Help

    Button AI Assistant Debuts, Offering Screen‑Free Voice Help

    Nostalgic iPod Shuffle design meets privacy‑first press‑to‑talk AI

    about 6 hours ago
    Razer Hammerhead V3 HyperSpeed Debuts with Dual‑Mode Case

    Razer Hammerhead V3 HyperSpeed Debuts with Dual‑Mode Case

    The USB‑C case also serves as a 2.4 GHz receiver, cutting dongles for PS5 and phones

    about 6 hours ago
    Apple ships 6.2 million Macs Q1 2026, M5‑MacBook Pro leads

    Apple ships 6.2 million Macs Q1 2026, M5‑MacBook Pro leads

    Apple’s share rises to 9.5%, moving it into fourth place among global PC makers

    about 6 hours ago
    Galaxy S22 Ultra can be bricked after factory reset

    Galaxy S22 Ultra can be bricked after factory reset

    US owners report IMEI‑level lock that hands control to unknown administrator Numero LLC

    about 6 hours ago
    Mouse: P.I. for Hire arrives April 16 on PC, PS5, and Xbox

    Mouse: P.I. for Hire arrives April 16 on PC, PS5, and Xbox

    Modes: 4K 60 fps quality or 120 fps performance on PS5 and Xbox Series X

    about 6 hours ago
    YouTube Rolls Out Auto Speed for Premium Users

    YouTube Rolls Out Auto Speed for Premium Users

    The AI‑driven playback boost aims to cut dead air on long videos

    1 day ago
    Blackwell Set to Capture Majority of the 2026 GPU Market

    Blackwell Set to Capture Majority of the 2026 GPU Market

    GB300/B300 GPUs Push Blackwell to 71% of Shipments; Rubin Falls to 22%

    1 day ago
    Google launches AI avatar tool for Shorts on April 9, 2026

    Google launches AI avatar tool for Shorts on April 9, 2026

    Ages 18+ can create digital replicas, with Synth ID tags and a 3‑year auto‑delete

    1 day ago
    Mac OS X 10.0 Cheetah runs on Wii

    Mac OS X 10.0 Cheetah runs on Wii

    Ports Mac OS X 10.0 Cheetah to the Wii, showing the PowerPC 750CL can run an OS

    1 day ago
    DuoBell Beats ANC: Safer Cycling with Apple AirPods Max

    DuoBell Beats ANC: Safer Cycling with Apple AirPods Max

    A 750 Hz blind‑spot lets DuoBell cut through ANC on popular headphones

    1 day ago
    Škoda DuoBell prototype unveiled on April 5, 2026

    Škoda DuoBell prototype unveiled on April 5, 2026

    750 Hz pulse and 2,000 Hz chime cut through ANC, alerting riders faster at 15 mph

    1 day ago
    SteamGPT Leak Reveals Dual‑Role AI on Steam

    SteamGPT Leak Reveals Dual‑Role AI on Steam

    Leak shows AI handling support and cheat‑detection for millions on the platform

    1 day ago
    Oppo Pad mini challenges Apple with Snapdragon 8 Gen 5

    Oppo Pad mini challenges Apple with Snapdragon 8 Gen 5

    April 21: Oppo Pad mini 8.8‑inch, Snapdragon 8 Gen 5, 5.39 mm, 279 g, 144 Hz OLED

    1 day ago
    Apple to ship 3 million foldable iPhones by end‑2026

    Apple to ship 3 million foldable iPhones by end‑2026

    Limited rollout equals 12 % of iPhone volume and rivals Samsung’s 2.4 million Galaxy Z Fold 7 sales

    1 day ago
    Apple unveils iPhone 18 Pro, iPhone 18 Pro Max, and iPhone Ultra

    Apple unveils iPhone 18 Pro, iPhone 18 Pro Max, and iPhone Ultra

    Mockups match leaked renders; 20 million Samsung panels for iPhone Ultra

    2 days ago
    Sony launches Playerbase program for Gran Turismo 7

    Sony launches Playerbase program for Gran Turismo 7

    PlayStation gamers can win a flight, facial scan, and an avatar in Gran Turismo 7

    2 days ago
    Claude Mythos Preview Beats Opus 4.6 in Cybersecurity!

    Claude Mythos Preview Beats Opus 4.6 in Cybersecurity!

    Claude Mythos Preview for five partners—pricing after a 100 million token credit

    2 days ago
    ChatGPT and AI Tools Let Solo Founders Launch Fast

    ChatGPT and AI Tools Let Solo Founders Launch Fast

    With GitHub Copilot, a founder can code, design, and deliver an MVP in days

    3 days ago
    Android 17 beta adds Notification Rules

    Android 17 beta adds Notification Rules

    New rules let users silence, block, or highlight alerts; Samsung eyes One UI 9

    3 days ago
    Utah Starts 12‑Month AI Chatbot Pilot for Psychiatric Meds

    Utah Starts 12‑Month AI Chatbot Pilot for Psychiatric Meds

    Legion Health pilot offers refills for 15 meds, easing shortages in rural Utah

    3 days ago
    Loading...
banner
Tech/Software

Anthropic leak reveals Opus 4.7, Sonnet 4.8 in npm 2.1.88

31 March 2026

—

News

Rachel Stein

On March 30 and 31, 2025, Anthropic unintentionally exposed over 512,000 lines of TypeScript code from its Claude Code AI model through an npm source map file, a supply chain misstep that offers a rare window into the company's roadmap while underscoring a vulnerability that could ripple across any organization publishing JavaScript packages.

Why it matters: The exposure reveals previously undisclosed models (Opus 4.7, Sonnet 4.8, and a prototype named Capybara) alongside internal features such as a stealth "Cover Mode," a long term memory system called KAIROS, and even a virtual pet named BUDDY. More broadly, it highlights a systemic weakness in the software supply chain at a moment when credential leaks are accelerating at an unprecedented rate.

What they're saying: Anthropic has not issued a public statement. Industry analysts, however, note that the leak arrived during a broader surge in credential exposure across public code. GitGuardian's 5th edition State of Secrets Sprawl report, released on March 17, 2025, documented 28.65 million new hardcoded secrets in public GitHub commits during 2024 and an 81 percent year over year increase in AI service credential leaks.

Source map files translate minified JavaScript back to original source code, enabling debugging. When published publicly, they can be reverse engineered to reconstruct the original codebase.

Technical details of the exposure: The npm package version 2.1.88 included a .map file weighing 59.8 MB and covering roughly 1,900 files. Researchers extracted approximately 512,000 lines of TypeScript, revealing internal modules such as "Cover Mode" for stealth code contribution, the long term memory system KAIROS, a virtual pet named BUDDY, and a profanity based frustration tracker designed to gauge developer sentiment.

The pattern beneath the numbers: GitGuardian data shows commits co-authored by Claude Code exhibited a 3.2 percent secret leak rate, more than double the 1.5 percent baseline for all public commits. With public GitHub activity reaching 1.94 billion commits in 2024, a 43 percent year over year rise, the scale of the supply chain risk is no longer theoretical. It is structural.

Comparison with other major tech leaks: The 2024 Google Search documentation leak disclosed 350,000 lines of indexing code, while the Claude leak reveals 512,000 lines of active model logic and future model references, making the latter broader in scope and more directly tied to AI product roadmaps.

What's next: Experts warn that internal repositories are approximately six times more likely to contain hardcoded secrets, and 28 percent of leaks now originate from collaboration tools such as Slack, Jira, and Confluence. Moreover, 64 percent of valid secrets detected in 2022 remained active when re-tested in January 2025, indicating a persistent remediation gap that organizations have yet to close.

Recommended security measures for AI labs:

  1. Implement automated scanning of npm packages for accidental source map inclusion before publishing.
  2. Adopt secret management tools that rotate credentials on each commit.
  3. Enforce strict code review policies that flag hardcoded keys in both public and private repositories.
  4. Conduct regular penetration tests of the software supply chain, focusing on third party dependencies.
  5. Provide developer training on secure packaging practices and the risks of source map exposure.
  6. Integrate real time alerts for anomalous commit patterns using services like GitGuardian.
  7. Maintain an incident response playbook specific to supply chain breaches.

For a deeper look at Anthropic's model roadmap, see our earlier coverage of Claude Opus 4.5 for autonomous coding. The Claude Code leak underscores the urgent need for robust software supply chain security as AI development accelerates and the stakes of accidental exposure continue to rise.

What is this about?

  • News/
  • Rachel Stein/
  • Tech/
  • Software

Feed

    Button AI Assistant Debuts, Offering Screen‑Free Voice Help

    Button AI Assistant Debuts, Offering Screen‑Free Voice Help

    Nostalgic iPod Shuffle design meets privacy‑first press‑to‑talk AI

    about 6 hours ago
    Razer Hammerhead V3 HyperSpeed Debuts with Dual‑Mode Case

    Razer Hammerhead V3 HyperSpeed Debuts with Dual‑Mode Case

    The USB‑C case also serves as a 2.4 GHz receiver, cutting dongles for PS5 and phones

    about 6 hours ago
    Apple ships 6.2 million Macs Q1 2026, M5‑MacBook Pro leads

    Apple ships 6.2 million Macs Q1 2026, M5‑MacBook Pro leads

    Apple’s share rises to 9.5%, moving it into fourth place among global PC makers

    about 6 hours ago
    Galaxy S22 Ultra can be bricked after factory reset

    Galaxy S22 Ultra can be bricked after factory reset

    US owners report IMEI‑level lock that hands control to unknown administrator Numero LLC

    about 6 hours ago
    Mouse: P.I. for Hire arrives April 16 on PC, PS5, and Xbox

    Mouse: P.I. for Hire arrives April 16 on PC, PS5, and Xbox

    Modes: 4K 60 fps quality or 120 fps performance on PS5 and Xbox Series X

    about 6 hours ago
    YouTube Rolls Out Auto Speed for Premium Users

    YouTube Rolls Out Auto Speed for Premium Users

    The AI‑driven playback boost aims to cut dead air on long videos

    1 day ago
    Blackwell Set to Capture Majority of the 2026 GPU Market

    Blackwell Set to Capture Majority of the 2026 GPU Market

    GB300/B300 GPUs Push Blackwell to 71% of Shipments; Rubin Falls to 22%

    1 day ago
    Google launches AI avatar tool for Shorts on April 9, 2026

    Google launches AI avatar tool for Shorts on April 9, 2026

    Ages 18+ can create digital replicas, with Synth ID tags and a 3‑year auto‑delete

    1 day ago
    Mac OS X 10.0 Cheetah runs on Wii

    Mac OS X 10.0 Cheetah runs on Wii

    Ports Mac OS X 10.0 Cheetah to the Wii, showing the PowerPC 750CL can run an OS

    1 day ago
    DuoBell Beats ANC: Safer Cycling with Apple AirPods Max

    DuoBell Beats ANC: Safer Cycling with Apple AirPods Max

    A 750 Hz blind‑spot lets DuoBell cut through ANC on popular headphones

    1 day ago
    Škoda DuoBell prototype unveiled on April 5, 2026

    Škoda DuoBell prototype unveiled on April 5, 2026

    750 Hz pulse and 2,000 Hz chime cut through ANC, alerting riders faster at 15 mph

    1 day ago
    SteamGPT Leak Reveals Dual‑Role AI on Steam

    SteamGPT Leak Reveals Dual‑Role AI on Steam

    Leak shows AI handling support and cheat‑detection for millions on the platform

    1 day ago
    Oppo Pad mini challenges Apple with Snapdragon 8 Gen 5

    Oppo Pad mini challenges Apple with Snapdragon 8 Gen 5

    April 21: Oppo Pad mini 8.8‑inch, Snapdragon 8 Gen 5, 5.39 mm, 279 g, 144 Hz OLED

    1 day ago
    Apple to ship 3 million foldable iPhones by end‑2026

    Apple to ship 3 million foldable iPhones by end‑2026

    Limited rollout equals 12 % of iPhone volume and rivals Samsung’s 2.4 million Galaxy Z Fold 7 sales

    1 day ago
    Apple unveils iPhone 18 Pro, iPhone 18 Pro Max, and iPhone Ultra

    Apple unveils iPhone 18 Pro, iPhone 18 Pro Max, and iPhone Ultra

    Mockups match leaked renders; 20 million Samsung panels for iPhone Ultra

    2 days ago
    Sony launches Playerbase program for Gran Turismo 7

    Sony launches Playerbase program for Gran Turismo 7

    PlayStation gamers can win a flight, facial scan, and an avatar in Gran Turismo 7

    2 days ago
    Claude Mythos Preview Beats Opus 4.6 in Cybersecurity!

    Claude Mythos Preview Beats Opus 4.6 in Cybersecurity!

    Claude Mythos Preview for five partners—pricing after a 100 million token credit

    2 days ago
    ChatGPT and AI Tools Let Solo Founders Launch Fast

    ChatGPT and AI Tools Let Solo Founders Launch Fast

    With GitHub Copilot, a founder can code, design, and deliver an MVP in days

    3 days ago
    Android 17 beta adds Notification Rules

    Android 17 beta adds Notification Rules

    New rules let users silence, block, or highlight alerts; Samsung eyes One UI 9

    3 days ago
    Utah Starts 12‑Month AI Chatbot Pilot for Psychiatric Meds

    Utah Starts 12‑Month AI Chatbot Pilot for Psychiatric Meds

    Legion Health pilot offers refills for 15 meds, easing shortages in rural Utah

    3 days ago
    Loading...