Anthropic and the Claude Code source map leak
~513Klines in the source map
2.1.88Claude Code version
1,900+files analysed

One extra file in a package can turn internal code into public code. That is what happened with an npm package for Claude Code. A source map, normally used to trace compiled code back to its original files, was published with the release and quickly analysed by developers.

The internet added another story about a model called Mythos. Anthropic now describes Mythos officially, but it should still be kept separate from the source-map incident. One is a release-packaging error. The other is a limited-access model for cybersecurity and biology research.

What the Claude Code leak exposed

Analyses by Varonis, Zscaler and Rintaro describe package @anthropic-ai/claude-code 2.1.88 and its public source map. Their counts vary slightly, but point to roughly 1,900 files and 512,000–513,000 lines of TypeScript.

That does not by itself mean that customer conversations, API keys or a customer database were exposed. The package contained application source code. It was a serious release-process mistake, but it is not automatic evidence of a user-data breach.

When a headline includes a large number and the word “leak”, it is easy to fill in the missing parts. For a business, the useful questions are more practical: what was public, where did it come from and does it touch our own deployment?

Mythos is real, but it is a different story

Anthropic’s official Mythos page describes Mythos 5.1 as a model for cybersecurity and biology research. Access is limited to vetted organisations through trusted access programmes. The company’s Fable 5.1 and Mythos 5.1 announcement explains the different safeguards and availability.

Those pages do not establish that Mythos caused the Claude Code source-map leak. Treat the model’s availability and capabilities as a separate product story, with its own date and source.

What to check in your own team

If your team uses Claude Code, the source map alone is not a reason to delete your workflow. It is a good reason to check the basics:

  1. Verify the installation source. Use official registries and compare versions with Anthropic’s documentation.
  2. Review file access. The tool should not read directories unrelated to its task.
  3. Keep keys out of code. Store API keys in a protected environment with limited access.
  4. Rotate keys when exposure is plausible. Do it because of evidence or a real access path, not just a dramatic headline.

Security is not a property of a logo in an application header. It is the sum of decisions made around installation, permissions and data.

What changed at Anthropic

Anthropic has since announced higher limits for Claude and Claude Code and continued expanding its API capacity. If you are making a purchasing or migration decision from an older article, check the current pricing, limits and retention terms directly with Anthropic.

FAQ

Were my Claude conversations exposed?

The technical analyses describe a source map and application source code. That alone does not show that conversation history or API keys were exposed. If you have evidence that a key was public, revoke it and check your logs.

Is Mythos an official Anthropic model?

Yes. Anthropic describes Mythos 5.1 officially, with access limited to vetted organisations. It is separate from the Claude Code source-map incident.

Do I need to stop using Claude Code?

Check the package source, permissions and key handling first. For sensitive projects, use an isolated environment and require review before changes are merged.

Updated 22 September 2026 with AI assistance. The article links the technical analyses and Anthropic’s official product information so readers can distinguish evidence from assumption.