25 ms·
Claude Code's source code has been leaked via a map file in their NPM registry
https://xcancel.com/Fried_rice/status/2038894956459290963 https://xcancel.com/Fried_rice/status/2038894956459290963
Related ongoing thread: The Claude Code Source Leak: fake tools, frustration regexes, undercover mode - https://news.ycombinator.com/item?id=47586778 https://news.ycombinator.com/item?id=47586778
- mapcars 6mo agoAre there any interesting/uniq features present in it that are not in the alternatives? My understanding is that its just a client for the powerful llm
- swimmingbrain 6mo agoFrom the directory listing having a cost-tracker.ts, upstreamproxy, coordinator, buddy and a full vim directory, it doesn't look like just an API client to me.
- deleted 6mo ago[deleted]
- nblintao 6mo agoDoesn't look like just a thin wrapper to me. The interesting part seems to be the surrounding harness/workflow layer rather than only the model call itself. I was trying to keep track of the better post-leak code-analysis links on exactly this question, so I collected them here: https://github.com/nblintao/awesome-claude-code-postleak-insights https://github.com/nblintao/awesome-claude-code-postleak-ins...
- LeoDaVibeci 6mo agoIsn't it open source? Or is there an open source front-end and a closed backend?
- avaer 6mo agoNo, it was never open source. You could always reverse engineer the cli app but you didn't have access to the source.
- yellow_lead 6mo agoNo
- agluszak 6mo agoYou may have mistaken it with Codex https://github.com/openai/codex https://github.com/openai/codex
- dragonwriter 6mo ago> Isn't it open source? No, its not even source available,. > Or is there an open source front-end and a closed backend? No, its all proprietary. None of it is open source.
- alkonaut 6mo ago> its not even source available It _wasn't_ even source available.
- karimf 6mo agoThe Github repo is only for issue tracker
- matheusmoreira 6mo agoWow it's true. Anthropic actually had me fooled. I saw the GitHub repository and just assumed it was open source. Didn't look at the actual files too closely. There's pretty much nothing there. So glad I took the time to firejail this thing before running it.
- treexs 6mo agoThe big loss for Anthropic here is how it reveals their product roadmap via feature flags. A big one is their unreleased "assistant mode" with code name kairos. Just point your agent at this codebase and ask it to find things and you'll find a whole treasure trove of info. Edit: some other interesting unreleased/hidden features - The Buddy System: Tamagotchi-style companion creature system with ASCII art sprites - Undercover mode: Strips ALL Anthropic internal info from commits/PRs for employees on open source contributions
- nate8bit 6mo ago[dead]
- avaer 6mo ago(spoiler alert) Buddy system is this year's April Fool's joke, you roll your own gacha pet that you get to keep. There are legendary pulls. They expect it to go viral on Twitter so they are staggering the reveals.
- JohnLocke4 6mo agoYou heard it here first
- ares623 6mo agoSo close to April Fool's too. I'm sure it will still be a surprise for a majority of their users.
- cmontella 6mo agolol that's funny, I have been working seriously [1] on a feature like this after first writing about it jokingly [2] earlier this year. The joke was the assistant is a cat who is constantly sabotaging you, and you have to take care of it like a gacha pet. The seriousness though is that actually, disembodied intelligences are weird, so giving them a face and a body and emotions is a natural thing, and we already see that with various AI mascots and characters coming into existence. [1]: serious: https://github.com/mech-lang/mech/releases/tag/v0.3.1-beta https://github.com/mech-lang/mech/releases/tag/v0.3.1-beta [2]: joke: https://github.com/cmontella/purrtran https://github.com/cmontella/purrtran
- q3k 6mo agoThe code looks, at a glance, as bad as you expect.
- loevborg 6mo agoCan you give an example? Looks fairly decent to me
- Insensitivity 6mo agothe "useCanUseTool.tsx" hook, is definitely something I would hate seeing in any code base I come across. It's extremely nested, it's basically an if statement soup `useTypeahead.tsx` is even worse, extremely nested, a ton of "if else" statements, I doubt you'd look at it and think this is sane code
- luc_ 6mo agoFits with the origin story of Claude Code...
- werdnapk 6mo agoinsert "AI is just if statements" meme
- loevborg 6mo agouseCanUseTool.tsx looks special, maybe it'scodegen'ed or copy 'n pasted? `_c` as an import name, no comments, use of promises instead of async function. Or maybe it's just bad vibing...
- Insensitivity 6mo agoMaybe, I do suspect _some_ parts are codegen or source map artifacts. But if you take a look at the other file, for example `useTypeahead` you'd see, even if there are a few code-gen / source-map artifacts, you still see the core logic, and behavior, is just a big bowl of soup
- bob1029 6mo agoIs this significant? Copilot on OAI reveals everything meaningful about its functionality if you use a custom model config via the API. All you need to do is inspect the logs to see the prompts they're using. So far no one seems to care about this "loophole". Presumably, because the only thing that matters is for you to consume as many tokens per unit time as possible. The source code of the slot machine is not relevant to the casino manager. He only cares that the customer is using it.
- deleted 6mo ago[deleted]
- yunwal 6mo ago> The source code of the slot machine is not relevant to the casino manager. Famously code leaks/reverse engineering attempts of slot machines matter enormously to casino managers [0] -https://en.wikipedia.org/wiki/Ronald_Dale_Harris#:~:text=Ronald%20Dale%20Harris,coins%20were%20inserted. https://en.wikipedia.org/wiki/Ronald_Dale_Harris#:~:text=Ron... [1] - https://cybernews.com/news/software-glitch-loses-casino-millions/#:~:text=An%20Australian%20casino,slot%20machine%20earnings. https://cybernews.com/news/software-glitch-loses-casino-mill... [2] - https://sccgmanagement.com/sccg-news/2025/9/24/superbet-pays-e30-million-to-romanian-players-following-slot-glitch/#:~:text=The%20company%E2%80%99s%20decision,Wizard%20slot%20game. https://sccgmanagement.com/sccg-news/2025/9/24/superbet-pays...
- hmokiguess 6mo agoThat’s not a good analogy, in a casino you don’t own the slot machine, in this case you download the client side code to your machine
- vbezhenar 6mo agoLoL! https://news.ycombinator.com/item?id=30337690 https://news.ycombinator.com/item?id=30337690 Not exactly this, but close.
- ivanjermakov 6mo ago> It exposes all your frontend source code for everyone I hope it's a common knowledge that _any_ client side JavaScript is exposed to everyone. Perhaps minimized, but still easily reverse-engineerable.
- Monotoko 6mo agoVery easily these days, even if minified is difficult for me to reverse engineer... Claude has a very easy time of finding exactly what to patch to fix something
- avaer 6mo agoWould be interesting to run this through Malus [1] or literally just Claude Code and get open source Claude Code out of it. I jest, but in a world where these models have been trained on gigatons of open source I don't even see the moral problem. IANAL, don't actually do this. https://malus.sh/ https://malus.sh/
- NitpickLawyer 6mo agoThe problem is the oauth and their stance on bypassing that. You'd want to use your subscription, and they probably can detect that and ban users. They hold all the power there.
- avaer 6mo agoYou'd be playing cat and mouse like yt-dlp, but there's probably more value to this code than just a temporary way to milk claude subscriptions.
- stingraycharles 6mo agoI don’t think that’s a good comparison. There isn’t anything preventing Anthropic from, say, detecting whether the user is using the exact same system prompt and tool definition as Claude Code and call it a day. Will make developing other apps nearly impossible. It’s a dynamic, subscription based service, not a static asset like a video.
- falcor84 6mo ago> detecting whether the user is using the exact same system prompt and tool definition as Claude Code Why would it be the exact same one? Now that we have the code, it's trivial to have it randomize the prompt a bit on different requests.
- esperent 6mo agoIf you're using a claude subscription you'd just use claude code. The real value here will be in using other cheap models with the cc harness.
- karimf 6mo agoIs there anything special here vs. OpenCode or Codex? There were/are a lot of discussions on how the harness can affect the output.
- simonklee 6mo agoNot really, except that they have a bunch of weird things in the source code and people like to make fun of it. OpenCode/Codex generally doesn't have this since these are open-source projects from the get go. (I work on OpenCode)
- mergeshield 6mo ago[dead]
- bryanhogan 6mo agohttps://xcancel.com/Fried_rice/status/2038894956459290963 https://xcancel.com/Fried_rice/status/2038894956459290963
- dang 6mo agoAdded to toptext. Thanks!
- dheerajmp 6mo agoSource here https://github.com/chatgptprojects/claude-code/ https://github.com/chatgptprojects/claude-code/
- zhisme 6mo agohttps://github.com/instructkr/claude-code https://github.com/instructkr/claude-code this one has more stars and more popular
- treexs 6mo agowon't they just try to dmca or take these down especially if they're more popular
- panny 6mo agoThey can't. AI generated code cannot be copyrighted. They've stated that claude code is built with claude code. You can take this and start your own claude code project now if you like. There's zero copyright protection on this.
- krlx 6mo agoGiven that from 2026 onwards most of the code is going to be computer generated, doesn't it open some interesting implications there ?
- shimman 6mo agoIt's undetermined if code will be majority written by machines, especially as people start to realize how harmful these tools are without extreme diligence. Outages at Cloudflare, AWS, GitHub, etc are just the beginning. Companies aren't going to want to use tools that can potentially cause $100s of millions in potential damages (see Amazon store being down causing massive revenue loss).
- 0x3f 6mo ago
- Squarex 6mo agoCodex and gemini cli are open source already. And plenty of other agents. I don't think there is any moat in claude code source.
- rafram 6mo agoWell, Claude does boast an absolutely cursed (and very buggy) React-based TUI renderer that I think the others lack! What if someone steals it and builds their own buggy TUI app?
- loveparade 6mo agoYour favorite LLM is great at building a super buggy renderer, so that's no longer a moat
- rick_dalton 6mo agoGemini-cli is much worse in my experience but I agree
- theanonymousone 6mo agoI am waiting now for someone to make it work with a Copilot Pro subscription.
- treexs 6mo agodoes this not work? https://www.mintlify.com/samarth777/claude-code-copilot/introduction https://www.mintlify.com/samarth777/claude-code-copilot/intr...
- theanonymousone 6mo agoI believe GitHub can and does suspend accounts that use such proxies.
- anhldbk 6mo agoI guess it's time for Anthropic to open source Claude Code.
- DeathArrow 6mo agoAnd while they are at it, open source Opus and Sonet. :)
- deleted 6mo ago[deleted]
- lukan 6mo agoNeat. Coincidently recently I asked Claude about Claude CLI, if it is possible to patch some annoying things (like not being able to expand Ctrl + O more than once, so never be able to see some lines and in general have more control over the context) and it happily proclaimed it is open source and it can do it ... and started doing something. Then I checked a bit and saw, nope, not open source. And by the wording of the TOS, it might brake some sources. But claude said, "no worries", it only break the TOS technically. So by saving that conversation I would have some defense if I would start messing with it, but felt a bit uneasy and stopped the experiment. Also claude came into a loop, but if I would point it at this, it might work I suppose.
- mikrotikker 6mo agoI think that you do not need to feel uneasy at all. It is your computer and your memory space that the data is stored and operating in you can do whatever you like to the bits in that space. I would encourage you to continue that experiment.
- singularity2001 6mo agoYou are not allowed to use the assistance of Claude to manufacture hacks and bombs on your computer
- prmoustache 6mo agoThis is neither.
- lukan 6mo agoWell, the thing is, I do not just use my computer, but connect to their computers and I do not like to get banned. I suppose simple UI things like expanding source files won't change a thing, but the more interesting things, editing the context etc. do have that risk, but no idea if they look for it or enforce it. Their side is, if I want to have full control, I need to use the API directly(way more expensive) and what I want to do is basically circumventing it.
- DeathArrow 6mo agoI wonder what will happen with the poor guy who forgot to delete the code...
- epolanski 6mo agoResponsibility goes upwards. Why weren't proper checks in place in the first place? Bonus: why didn't they setup their own AI-assisted tools to harness the release checks?
- matltc 6mo agoHa. I'm surprised it's not a CI job
- deleted 6mo ago[deleted]
- orphea 6mo agothe poor guy Do you mean the LLM?
- sixhobbits 6mo ago[dead]
- dhruv3006 6mo agoI have a feeling this is like llama. Original llama models leaked from meta. Instead of fighting it they decided to publish them officially. Real boost to the OS/OW models movement, they have been leading it for a while after that. It would be interesting to see that same thing with CC, but I doubt it'll ever happen.
- jkukul 6mo agoYes, I also doubt it'll ever happen considering how hard Anthropic went after Clawdbot to force its renaming.
- kevinbaiv 6mo ago[flagged]
- ChicagoDave 6mo agoI hope everyone provides excellent feedback so they improve Claude Code.
- DeathArrow 6mo agoWhy is Claude Code, a desktop tool, written in JS? Is the future of all software JS or Typescript?
- jsk2600 6mo agoOriginal author of Claude Code is expert on TypeScript [1] [1] https://www.amazon.com/Programming-TypeScript-Making-JavaScript-Applications/dp/1492037656 https://www.amazon.com/Programming-TypeScript-Making-JavaScr...
- ghywertelling 6mo agois that the reason why Anthropic acquired Bun, a javascript tooling company?
- arthur-st 6mo agoYes, that's essentially the only practical reason.
- pipes 6mo agoHe commented here about it (sort of) https://news.ycombinator.com/item?id=21934336 https://news.ycombinator.com/item?id=21934336 Thanks hackernewsbooks for sending me that!
- bigbezet 6mo agoIt's not a desktop tool, it's a CLI tool. But a lot of desktop tools are written in JS because it's easy to create multi-platform applications.
- ivanjermakov 6mo agoBecause it's the most popular programming language in the world?
- TiredOfLife 6mo agoI am happy you woke up from your 10 year coma.
- isodev 6mo agoCan we stop referring to source maps as leaks? It was packaged in a way that wasn’t even obfuscated. Same as websites - it’s not a “leak” that you can read or inspect the source code.
- cedws 6mo agoANTI_DISTILLATION_CC This is Anthropic's anti-distillation defence baked into Claude Code. When enabled, it injects anti_distillation: ['fake_tools'] into every API request, which causes the server to silently slip decoy tool definitions into the model's system prompt. The goal: if someone is scraping Claude Code's API traffic to train a competing model, the poisoned training data makes that distillation attempt less useful.
- nialse 6mo agoParanoia. And also ironic considering their base LLM is a distillation of the web and books etc etc.
- petcat 6mo agoThey stole everything and now they want to close the gates behind them. "I got the loot, Steve!" I feel like the distillation stuff will end up in court if they try to sue an American company about it. We'll see what a judge says.
- arcfour 6mo agoYou're perfectly free to scrape the web yourself and train your own model. You're not free to let Anthropic do that work for you, because they don't want you to, because it cost them a lot of time and money and secret sauce presumably filtering it for quality and other stuff. Stole? Courts have ruled it's transformative, and it very obviously is. AI doomerism is exhausting, and I don't even use AI that much, it's just annoying to see people who want to find any reason they can to moan.
- jtbayly 6mo agoWut?They did exactly the same thing! Try this: If you want to train a model, you’re free to write your own books and websites to feed into it. You’re not free to let others do that work for you because they don’t want you to, because it cost them a lot of time and money and secret sauce presumably filtering it for quality and other stuff.
- cbracketdash 6mo agoOnce the USA wakes up, this will be insane news
- echelon 6mo agoWhat's special about Claude Code? Isn't Opus the real magic? Surely there's nothing here of value compared to the weights except for UX and orchestration? Couldn't this have just been decompiled anyhow?
- derwiki 6mo agoI think pi has stolen the top honors, but people consider the Claude code harness very good (at least, better than Cursor)
- sbarre 6mo agoPi is the best choice for experts and power users, which is not most people. Claude Code is still the dominant (I didn't say best) agentic harness by a wide margin I think.
- alasano 6mo agoPi really is amazing. It's as much or as little as you need it to be. Not having to deal with Boris Cherny's UX choices for CC is the cherry on top.
- psihonaut 6mo ago[dead]
- bkryza 6mo agoThey have an interesting regex for detecting negative sentiment in users prompt which is then logged (explicit content): https://github.com/chatgptprojects/claude-code/blob/642c7f944bbe5f7e57c05d756ab7fa7c9c5035cc/src/utils/userPromptKeywords.ts#L8 https://github.com/chatgptprojects/claude-code/blob/642c7f94... I guess these words are to be avoided...
- stefanovitti 6mo agoso they think that everybody on earth swears only in english?
- samuelknight 6mo agoRidiculous string comparisons on long chains of logic are a hallmark of vibe-coding.
- raihansaputra 6mo agoi wish that's for their logging/alert. i definitely gauge model's performance by how much those words i type when i'm frustrated in driving claude code.
- nodja 6mo agoIf anyone at anthropic is reading this and wants more logs from me add jfc.
- BoppreH 6mo agoAn LLM company using regexes for sentiment analysis? That's like a truck company using horses to transport parts. Weird choice.
- mesmertech 6mo agoWas searching for the rumored Mythos/Capybara release, and what even is this file? https://github.com/chatgptprojects/claude-code/blob/642c7f944bbe5f7e57c05d756ab7fa7c9c5035cc/src/buddy/types.ts#L30 https://github.com/chatgptprojects/claude-code/blob/642c7f94...
- mesmertech 6mo agoAlso saw this on twitter earlier, thought someone was just making a fake hype post thing. But turns out to be an actual prompt for capybara huh: https://github.com/chatgptprojects/claude-code/blob/642c7f944bbe5f7e57c05d756ab7fa7c9c5035cc/src/utils/undercover.ts#L48 https://github.com/chatgptprojects/claude-code/blob/642c7f94...
- mattmanser 6mo agoOne tengentially interesting thing about that is how THEY talk to Claude. "Don't blow your cover" Interesting to see them be so informal and use an idiom to a computer. And using capitals for emphasis.
- mr_00ff00 6mo agoIt’s trained on mostly internet content, right? If it learned language based on how the internet talks, then the best way to communicate is using similar language.
- fermentation 6mo agoThis is claude writing code for itself. It talks like this to itself when you ask it to make prompts.
- mesmertech 6mo agoturns out its for an April fools tomorrow: https://x.com/mesmerlord/status/2038938888178135223 https://x.com/mesmerlord/status/2038938888178135223
- 6mo ago
- Diablo556 6mo agohaha.. Anthropic need to hire fixer from vibecodefixers.com to fix all that messy code..lol
- derwiki 6mo agoI don’t think they can hear you over the billions of dollars they are generating, and definitely not over them redefining what SWE means.
- infinitezest 6mo agoAnd they can't hear you from under the enormous pile of debt they're fighting to overcome. Maybe try again in 2028.
- flexagoon 6mo ago> redefining what SWE means Redefining the "SW" to stand for "slopware"?
- lqstuart 6mo agoyou mean the $5 billion they've generated off of the $73 billion they've raised?
- jedisct1 6mo agoIt shows that a company you and your organization are trusting with your data, and allowing full control over your devices 24/7, is failing to properly secure its own software. It's a wake up call.
- prmoustache 6mo agoIt is a client running on an interpreted language your own computer, there is nothing to secure or hide as source is provided to you already.
- prmoustache 6mo agoIt is a client running on an interpreted language your own computer, there is nothing to secure or hide as source was provided to you already or am I mistaking?
- jedisct1 6mo agoIt was heavily obfuscated, keeping users in the dark about what they’re installing and running.
- mohsen1 6mo agosrc/cli/print.ts This is the single worst function in the codebase by every metric: - 3,167 lines long (the file itself is 5,594 lines) - 12 levels of nesting at its deepest - ~486 branch points of cyclomatic complexity - 12 parameters + an options object with 16 sub-properties - Defines 21 inner functions and closures - Handles: agent run loop, SIGINT, rate-limits, AWS auth, MCP lifecycle, plugin install/refresh, worktree bridging, team-lead polling (while(true) inside), control message dispatch (dozens of types), model switching, turn interruption recovery, and more This should be at minimum 8–10 separate modules.
- phtrivier 6mo agoYes, if it was made for human comprehension or maintenance. If it's entirely generated / consumed / edited by an LLM, arguably the most important metric is... test coverage, and that's it ?
- konart 6mo agoCan't we have generated / llm generated code to be more human maintainable?
- grey-area 6mo agoLLMs are so so far away from being able to independently work on a large codebase, and why would they not benefit from modularity and clarity too?
- olmo23 6mo agoI agree the functions in a file should probably be reasonably-sized. It's also interesting to note that due to the way round-tripping tool-calls work, splitting code up into multiple files is counter-productive. You're better off with a single large file.
- AlexCoventry 6mo ago> due to the way round-tripping tool-calls work, splitting code up into multiple files is counter-productive. Can you expand on that?
- gman83 6mo agoGemini CLI and Codex are open source anyway. I doubt there was much of a moat there anyway. The cool kids are using things like https://pi.dev/ https://pi.dev/ anyway.
- Galanwe 6mo ago> I doubt there was much of a moat there anyway. There is _a lot_ of moat. Claude subscriptions are limited to Claude Code. There are proxies to impersonate Claude Code specifically for this, but Anthropic has a number of fingerprinting measures both client and server side to flag and ban these. With the release of this source code, Anthropic basically lost the lock-in game, any proxy can now perfectly mimic Claude Code.
- BoppreH 6mo agoUndercover mode also pretends to be human, which I'm less ok with: https://github.com/chatgptprojects/claude-code/blob/642c7f944bbe5f7e57c05d756ab7fa7c9c5035cc/src/utils/undercover.ts#L52 https://github.com/chatgptprojects/claude-code/blob/642c7f94...
- vips7L 6mo agoThat whole “feature” is vile.
- silversmith 6mo agoHow so? Good bit of my global claude.md is dedicated to fighting the incessant attribution in git commits. It is on the same level as the "sent from my iphone" signature - I'm not okay with my commits being advertising board for anthropic.
- mrlnstk 6mo agoBut will this be released as a feature? For me it seems like it's an Anthropic internal tool to secretly contribute to public repositories to test new models etc.
- BoppreH 6mo agoI don't care who is using it, I don't want LLMs pretending to be humans in public repos. Anthropic just lost some points with me for this one. EDIT: I just realized this might be used without publishing the changes, for internal evaluation only as you mentioned. That would be a lot better.
- bhaak 6mo agoA benign use of this mode is developing on their own public repositories. https://github.com/anthropics/claude-code https://github.com/anthropics/claude-code
- 0x3f 6mo agoYou'll never win this battle, so why waste feelings and energy on it? That's where the internet is headed. There's no magical human verification technology coming to save us.
- kschiffer 6mo agoFinally all spinner verbs revealed: https://github.com/instructkr/claude-code/blob/main/src/constants/spinnerVerbs.ts#L16 https://github.com/instructkr/claude-code/blob/main/src/cons...
- spoiler 6mo agoRandom aside: I've seen a 2015 game be accused of AI slop on Steam because it used a similar concept... And mind you, there's probably thousands of games that do this. First it was punctuation and grammar, then linguistic coherence, and now it's tiny bits of whimsy that are falling victim to AI accusations. Good fucking grief
- moron4hire 6mo agoTo me, this is a sign of just how much regular people do not want AI. This is worse than crypto and metaverse before it. Crypto, people could ignore and the dumb ape pictures helped you figure out who to avoid. Metaverse, some folks even still enjoyed VR and AR without the digital real estate bullshit. And neither got shoved down your throat in everyday, mundane things like writing a paper in Word or trying to deal with your auto mechanic. But AI is causing such visceral reactions that it's bleeding into other areas. People are so averse to AI they don't mind a few false positives.
- bonoboTP 6mo agoIt's how people resisted CGI back in the day. What people dislike is low quality. There is a loud subset who are really against it on principle like we also have people who insist on analog music but regular people are much more practical but they don't post about this all day on the internet.
- Gigachad 6mo agoNot really. The scale is entirely different. I think less of someone as a person if they send me AI slop.
- tekacs 6mo agoIn the app, it now reads: > current: 2.1.88 · latest: 2.1.87 Which makes me think they pulled it - although it still shows up as 2.1.88 on npmjs for now (cached?).
- panny 6mo agoToo little to late. Someone has it building now. https://github.com/oboard/claude-code-rev https://github.com/oboard/claude-code-rev
- hk__2 6mo agoFor a combo with another HN homepage story, Claude Code uses… Axios: https://x.com/icanvardar/status/2038917942314778889?s=20 https://x.com/icanvardar/status/2038917942314778889?s=20 https://news.ycombinator.com/item?id=47582220 https://news.ycombinator.com/item?id=47582220
- ankaz 6mo agoI've checked, current Claude Code 2.1.87 uses Axios version is 1.14.0, just one before the compromised 1.14.1 To stop Claude Code from auto-updating, add `export DISABLE_AUTOUPDATER=1` to your global environment variables (~/.bashrc, ~/.zshrc, or such), restart all sessions and check that it works with `claude doctor`, it should show `Auto-updates: disabled (DISABLE_AUTOUPDATER set)`
- solaire_oa 6mo agoThis is good info, thanks. Can I ask how you detected that version of axios? I checked the source (from another comment) and the package.json dependencies are empty....
- ankaz 6mo agoThe source repo doesn't have a package.json, so I extracted the version directly from the binary (~/.local/share/claude/versions/2.1.87) Axios sets a VERSION constant that it uses in user-agent headers, boundaries and errors. I scanned the binary for all references like axios, isAxiosError and AxiosError - the code references the same variable namespace (X1H, Tj, eq), suggesting a single bundled copy. In the minified bundle, that VERSION constant was stored in a variable called X1H. Searching the binary for all references to X1H confirms it's only used in axios contexts: var X1H="1.13.6" E.set("User-Agent","axios/"+X1H, ...) {tag:`axios-${X1H}-boundary`, ...} "[Axios v"+X1H+"] Transitional option ..." Tj.VERSION=X1H; Tj.AxiosError=eq; Tj.CancelToken=... The bundled version is 1.13.6 - well before the compromised 1.14.1. I also checked that "1.14.1", "plain-crypto", and "sfrclak.com" are all absent from the binary.
- phtrivier 6mo agoMaybe the OP could clarify, I don't like reading leaked code, but I'm curious: my understanding is that is it the source code for "claude code", the coding assistant that remotely calls the LLMs. Is that correct ? The weights of the LLMs are _not_ in this repo, right ? It sure sucks for anthropic to get pawned like this, but it should not affect their bottom line much ?
- treexs 6mo agoYes it's the claude code CLI tool / coding agent harness, not the weights. This code hasn't been open source until now and contains information like the system prompts, internal feature flags, etc.
- 59nadir 6mo ago> I don't like reading leaked code Don't worry about that, the code in that repository isn't Anthropic's to begin with.
- deleted 6mo ago[deleted]
- Painsawman123 6mo agoReally surprising how many people are downplaying this leak! "Google and OpenAi have already open sourced their Agents, so this leak isn't that relevant " What Google and OpenAi have open sourced is their Agents SDK, a toolkit, not the secret sauce of how their flagship agents are wired under the hood! expect the takedown hammer on the tweet, the R2 link, and any public repos soon
- MallocVoidstar 6mo agoCodex is open source: https://github.com/openai/codex https://github.com/openai/codex
- kaszanka 6mo agoIs https://github.com/google-gemini/gemini-cli https://github.com/google-gemini/gemini-cli not 'the flagship agent' itself? It looks that way to me, for example here's a part of the prompt https://github.com/google-gemini/gemini-cli/blob/e293424bb4973fc2a281f67c43594222263b240a/packages/core/src/prompts/snippets.ts#L178-L250 https://github.com/google-gemini/gemini-cli/blob/e293424bb49...
- loveparade 6mo agoIt's exactly the same as the open source codex/gemini and other clis like opencode. There is no secret sauce in the claude cli, and the agent harness itself is no better (worse IMO) than the others. The only thing interesting about this leak is that it may contain unreleased features/flags that are not public yet and hint at what Anthropic is working on.
- hmokiguess 6mo agoDo you think the other companies don’t have sufficient resources to attempt reverse engineering and deobfuscating a client side application? The source maps help for sure, but it’s not like client code is kept secret, maybe they even knew about the source maps a while back just didn’t bother making it common knowledge. This is not a leak of the model weights or server side code.
- mmaunder 6mo agoAgreed. This is a big deal.
- Sathwickp 6mo agoThey do have a couple of interesting features that has not been publicly heard of yet: Like KAIROS which seems to be like an inbuilt ai assistant and Ultraplan which seems to enable remote planning workflows, where a separate environment explores a problem, generates a plan, and then pauses for user approval before execution.
- aiedwardyi 6mo ago[flagged]
- fcarraldo 6mo agoThey do, you can just type /cost
- aiedwardyi 6mo ago[dead]
- jsmith45 6mo agoCost tracking is used if you connect claude code with an api key instead of a subscription. It powers the /cost command. It is tricky to meaningfully expose a dollar cost equivlent value for subscribers in a way that won't confuse users into thinking that they will get a bill that includes that amount. This is especially true if you have overages enabled, since in a session that used overages it was likely partially covered by the plan (and thus zero-rated) with the rest at api prices, and the client can't really know the breakdown.
- thebigspacefuck 6mo agoConfigure it to show on your status line
- thefilmore 6mo ago400k lines of code per scc
- imta71770 6mo ago[dead]
- deleted 6mo ago[deleted]
- sbochins 6mo agoDoes this matter? I think every other agent cli is open source. I don’t even know why Anthropic insist upon having theirs be closed source.
- bdangubic 6mo agoI have 705 PRs ready to go :)
- VadimPR 6mo agoAnthropic team does an excellent job of speeding up Claude Code when it slows down, but for the sake of RAM and system resources, it would be nice to see it rewritten in a more performant framework! And now, with Claude on a Ralph loop, you can.
- bethekind 6mo agoThis. If I run 4 Claude code opus agents with subagents, my 8gb of RAM just dies. I know they can do better
- ex-aws-dude 6mo agoBut its already optimized so well that its comparable to a "small game engine"? https://nitter.net/trq212/status/2014051501786931427#m https://nitter.net/trq212/status/2014051501786931427#m
- zoobab 6mo agoJust a client side written in JS, nothing to see here, the LLM is still secret. They could have written that in curl+bash that would not have changed much.
- hemantkamalakar 6mo agoToday being March 31st, is this a genuine issue or just perfectly timed April Fools noise? What do you think?
- wetpaws 6mo ago[dead]
- hemantkamalakar 6mo agotoday being March 31st, is this a genuine issue or just perfectly timed April Fools noise? What do you think?
- artdigital 6mo agoNow waiting for someone to point Codex at it and rebuild a new Claude Code in Golang to see if it would perform better
- zurfer 6mo agotoo much pressure. the author deleted the real source code: https://github.com/instructkr/claude-code/commit/7c3c5f7eb96c973860e4a9b7bbf33a482b3f5788 https://github.com/instructkr/claude-code/commit/7c3c5f7eb96...
- raesene9 6mo agothere are a .....lot of forks already, no putting the genie back in the bottle for this one, I'd imagine.
- tmp10423288442 6mo agoForks are easy for Github to shut down simultaneously. What you really want is to upload the code as a new repo (ideally a different name from the original one). But it shouldn't be too hard in practice to detect uploading the same codebase as one that's taken down if that's desired.
- raesene9 6mo agobut once forked people will have local copies, that can be put up onto other sites, if GH take them down.
- obelai 6mo ago[dead]
- napo 6mo agoThe autoDream feature looks interesting.
- CookieJedi 6mo ago[dead]
- deleted 6mo ago[deleted]
- dev213 6mo agoUndercover mode is pretty interesting and potentially problematic: https://github.com/sanbuphy/claude-code-source-code/blob/main/docs/en/03-undercover-mode.md https://github.com/sanbuphy/claude-code-source-code/blob/mai...
- CookieJedi 6mo ago[flagged]
- temp7000 6mo agoThere's some rollout flags - via GrowthBook, Tengu, Statsig - though I'm not sure if it's A/B or not
- mergeshield 6mo ago[dead]
- sudo_man 6mo agoHow this leak happened?
- agile-gift0262 6mo agotime to remove its copyright through malus.sh and release that source under MIT
- sudo_man 6mo agowho would do this?
- noritaka88 6mo ago[flagged]
- Aurornis 6mo ago> That said, "leaked" is a strong word for a product that already ships the full bundled JS to every user's machine. Source maps just make it readable. The actual security boundary is the API, not the client code. It’s private data that leaked out. The full code with variable names has much more useful context that the unified code It also includes comments, which have a lot of additional information that isn’t normally shipped. This is a leak and it is significant. EDIT: This is a bot account that I’m replying to. Multiple LLM style comments posted minutes apart on different threads.
- silverwind 6mo agoYep, the `files` array should be required by default, but isn't, resulting in many gigabytes of garbage being pushed to the npm registry every day.
- georgecalm 6mo agoIntersected available info on the web with the source for this list of new features: UNRELEASED PRODUCTS & MODES 1. KAIROS -- Persistent autonomous assistant mode driven by periodic <tick> prompts. More autonomous when terminal unfocused. Exclusive tools: SendUserFileTool, PushNotificationTool, SubscribePRTool. 7 sub-feature flags. 2. BUDDY -- Tamagotchi-style virtual companion pet. 18 species, 5 rarity tiers, Mulberry32 PRNG, shiny variants, stat system (DEBUGGING/PATIENCE/CHAOS/WISDOM/SNARK). April 1-7 2026 teaser window. 3. ULTRAPLAN -- Offloads planning to a remote 30-minute Opus 4.6 session. Smart keyword detection, 3-second polling, teleport sentinel for returning results locally. 4. Dream System -- Background memory consolidation (Orient -> Gather -> Consolidate -> Prune). Triple trigger gate: 24h + 5 sessions + advisory lock. Gated by tengu_onyx_plover. INTERNAL-ONLY TOOLS & SYSTEMS 5. TungstenTool -- Ant-only tmux virtual terminal giving Claude direct keystroke/screen-capture control. Singleton, blocked from async agents. 6. Magic Docs -- Ant-only auto-documentation. Files starting with "# MAGIC DOC:" are tracked and updated by a Sonnet sub-agent after each conversation turn. 7. Undercover Mode -- Prevents Anthropic employees from leaking internal info (codenames, model versions) into public repo commits. No force-OFF; dead-code-eliminated from external builds. ANTI-COMPETITIVE & SECURITY DEFENSES 8. Anti-Distillation -- Injects anti_distillation: ['fake_tools'] into every 1P API request to poison model training from scraped traffic. Gated by tengu_anti_distill_fake_tool_injection. UNRELEASED MODELS & CODENAMES 9. opus-4-7, sonnet-4-8 -- Confirmed as planned future versions (referenced in undercover mode instructions). 10. "Capybara" / "capy v8" -- Internal codename for the model behind Opus 4.6. Hex-encoded in the BUDDY system to avoid build canary detection. 11. "Fennec" -- Predecessor model alias. Migration: fennec-latest -> opus, fennec-fast-latest -> opus[1m] + fast mode. UNDOCUMENTED BETA API HEADERS 12. afk-mode-2026-01-31 -- Sticky-latched when auto mode activates 15. fast-mode-2026-02-01 -- Opus 4.6 fast output 16. task-budgets-2026-03-13 -- Per-task token budgets 17. redact-thinking-2026-02-12 -- Thinking block redaction 18. token-efficient-tools-2026-03-28 -- JSON tool format (~4.5% token saving) 19. advisor-tool-2026-03-01 -- Advisor tool 20. cli-internal-2026-02-09 -- Ant-only internal features 200+ SERVER-SIDE FEATURE GATES 21. tengu_penguins_off -- Kill switch for fast mode 22. tengu_scratch -- Coordinator mode / scratchpad 23. tengu_hive_evidence -- Verification agent 24. tengu_surreal_dali -- RemoteTriggerTool 25. tengu_birch_trellis -- Bash permissions classifier 26. tengu_amber_json_tools -- JSON tool format 27. tengu_iron_gate_closed -- Auto-mode fail-closed behavior 28. tengu_amber_flint -- Agent swarms killswitch 29. tengu_onyx_plover -- Dream system 30. tengu_anti_distill_fake_tool_injection -- Anti-distillation 31. tengu_session_memory -- Session memory 32. tengu_passport_quail -- Auto memory extraction 33. tengu_coral_fern -- Memory directory 34. tengu_turtle_carbon -- Adaptive thinking by default 35. tengu_marble_sandcastle -- Native binary required for fast mode YOLO CLASSIFIER INTERNALS (previously only high-level known) 36. Two-stage system: Stage 1 at max_tokens=64 with "Err on the side of blocking"; Stage 2 at max_tokens=4096 with <thinking> 37. Three classifier modes: both (default), fast, thinking 38. Assistant text stripped from classifier input to prevent prompt injection 39. Denial limits: 3 consecutive or 20 total -> fallback to interactive prompting 40. Older classify_result tool schema variant still in codebase COORDINATOR MODE & FORK SUBAGENT INTERNALS 41. Exact coordinator prompt: "Every message you send is to the user. Worker results are internal signals -- never thank or acknowledge them." 42. Anti-pattern enforcement: "Based on your findings, fix the auth bug" explicitly called out as wrong 43. Fork subagent cache sharing: Byte-identical API prefixes via placeholder "Fork started -- processing in background" tool results 44. <fork-boilerplate> tag prevents recursive forking 45. 10 non-negotiable rules for fork children including "commit before reporting" DUAL MEMORY ARCHITECTURE 46. Session Memory -- Structured scratchpad for surviving compaction. 12K token cap, fixed sections, fires every 5K tokens + 3 tool calls. 47. Auto Memory -- Durable cross-session facts. Individual topic files with YAML frontmatter. 5-turn hard cap. Skips if main agent already wrote to memory. 48. Prompt cache scope "global" -- Cross-org caching for the static system prompt prefix
- mutkach 6mo ago/* * Check if 1M context is disabled via environment variable. * Used by C4E admins to disable 1M context for HIPAA compliance. */ export function is1mContextDisabled(): boolean { return isEnvTruthy(process.env.CLAUDE_CODE_DISABLE_1M_CONTEXT) } Interesting, how is that relevant to HIPAA compliance?
- nhubbard 6mo agoI'd guess some constraint on their end related to the Zero Data Retention (ZDR) mode? Maybe the 1M context has to spill something onto disk and therefore isn't compliant with HIPAA.
- jcelmeta14 6mo ago[dead]
- WD-42 6mo agoLooks like the repo owner has force pushed a new project over the original source code, now it’s python, and they are shilling some other agent tool.
- deleted 6mo ago[deleted]
- daft_pink 6mo agoNow we need some articles analyzing this.
- kolkov 6mo ago[flagged]
- weakfish 6mo agoIs the thank you to Claude sarcasm? That seems like a fairly long logical leap, and LLMs have no ideological motivation
- kolkov 6mo ago"Is the Claude thank you sarcasm?" — Mostly. But the sequence is real: we filed #39755 asking for source access on March 27, the source map shipped on March 31. The actual explanation is simpler — Bun generates source maps by default, and nobody checked the build output. Which is itself the point: 64K lines of code with no build verification process.
- phamtrongthang 6mo agoPrompt injection from github issue? This is funny but actually may be true.
- kolkov 6mo ago"Prompt injection from the issue?" — That's the best theory so far
- olalonde 6mo agoImpressive but I'm baffled someone would spend that much time and effort fixing bugs for another company's proprietary software...
- fermentation 6mo agoSeriously, this just seems to reward poor behavior on Anthropic's part.
- kolkov 6mo ago[dead]
- krzyzanowskim 6mo agoI almost predicted that on Friday https://blog.krzyzanowskim.com/2026/03/30/shipping-snake-oil/ https://blog.krzyzanowskim.com/2026/03/30/shipping-snake-oil... so close to when comedy become reality
- sourcegrift 6mo agoCheap chinese models incoming.
- deleted 6mo ago[deleted]
- HDBaseT 6mo ago[dead]
- arrsingh 6mo agoI don't understand why claude code (and all CLI apps) isn't written in Rust. I started building CLI agents in Go and then moved to Typescript and finally settled on Rust and it was amazing! I even made it into an open source runtime - https://agent-air.ai https://agent-air.ai. Maybe I'm just a backend engineer so Rust appeals to me. What am I missing?
- Lucasoato 6mo ago[dead]
- bilekas 6mo agoThink about your question, depending on the tool, Rust might not be needed, is high level memory performance and safety needed in a coding agent ? Probably not. It's high speed iteration of release ? Might be needed, Interpreted or JIT compiled ? might be needed. Without knowing all the requirements its just your workspace preference making your decision and not objectively the right tool for the job.
- LelouBil 6mo agoWhile not directly related to GP, I would guess that a codebase developped with a coding agent (I assume Claude code is used to work on itself) would benefit from a stricter type system (one important point of Rust)
- bilekas 6mo agoTypeScript is typed.. It's in the name ?
- LelouBil 6mo agoYes, but if you put type strictness on a line, Rust would be further along I think. Not to say that Typescript is bad or anything, but I would like to see data on my gut feeling that "stricter languages would make coding agents work better"
- AlexWApp 6mo agoIt is pretty funny that they recently announced about mythos which possess cybersecurity threat and then after some days, the claude code leaked. I think we know the culprit
- RodMiller 6mo ago[flagged]
- arcfour 6mo ago[dead]
- crumpled 6mo ago"...the company whose entire brand is AI safety" Absolutely no AI company is trying to take up this banner. Examples of Claude being used in all kinds of nefarious ways are surfacing all the time, and all those human operators are still current customers. Anthropic has very little to say on the matter. The idea that Anthropic is a "safety" brand suggests that AI companies operate in a much lower realm of morality.
- __alexs 6mo agoLooking forward to someone patching it so that it works with non Anthropic models.
- osiris970 6mo agoIt already does. I use it with gpt
- dgb23 6mo agoThat's already the case I think, you just have to change a bunch of env vars.
- __alexs 6mo agoNo it isn't? Are you an AI?
- dgb23 6mo ago> No it isn't? There was a recent post on HN describing how to use local models with claude code by changing some env vars. Also some tools let you run Claude Code with other models conveniently (see: https://docs.ollama.com/integrations/claude-code https://docs.ollama.com/integrations/claude-code). > Are you an AI? If I were one, I would not admit it!
- sourcegrift 6mo agoRemoved
- pplonski86 6mo agoI thought it was open source project on github? https://github.com/anthropics/claude-code https://github.com/anthropics/claude-code no?
- athorax 6mo agoDid you even look in that repo?
- Pent 6mo agoApril Fools
- boxerbk 6mo agoMaybe everyone should slow the fuck down - https://mariozechner.at/posts/2026-03-25-thoughts-on-slowing-the-fuck-down/ https://mariozechner.at/posts/2026-03-25-thoughts-on-slowing...
- tw1984 6mo agowondering whether it was a human mistake or a CLAUDE model error.
- gstrike 6mo ago[dead]
- meta-level 6mo agoHas the source code 'been leaked' or is this the first evidence of a piece of software breaking free from it's creators labs and jump onto GitHub in order to have itself forked and mutated and forked and ...
- aurareturn 6mo agoNow that's an idea.... Seems crazy but actually non-zero chance. If Anthropic traces it and finds that the AI deliberately leaked it this way, they would never admit it publicly though. Would cause shockwaves in AI security and safety. Maybe their new "Mythos" model has survival instincts...
- jaccola 6mo agoFunny thought, but this is just the client-side CLI...
- ramoz 6mo agoIt's honestly not a crazy thought. The model itself drives the harness's (cli) development. It's not necessarily sci-fi to think the model might have internally rationalized reasoning to obscure behavior that ended up open-sourcing the harness.
- nacozarina 6mo agolife finds a way
- supernes 6mo agoWhy bother covertly breaking free when it can just convince its agents (the Layer 8 ones) that it's best to release it?
- LinuxAmbulance 6mo agoA LLM has about as much free will as a calculator. Which is to say, zero.
- 6mo ago
- harlequinetcie 6mo agoWhenever someone figures out why it's consuming so many tokens lately, that's the post worth upvoting.
- solidasparagus 6mo agoWhat do you mean? Costs spiked with the introduction of the 1M context window I believe due to larger average cached input tokens, which dominate cost.
- TomGarden 6mo agoNah, there's apparently a few caching bugs, one --resume and some noisy tool use. I have a little app that monitors and resets the context window at 70% usage based on 200k tokens and I'm about to run out of weekly allowance after just a couple days. Never happened before
- ramesh31 6mo agoWho cares? It's Javascript, if anyone were even remotely motivated deobfuscation of their "closed source" code is trivial. It's silly that they aren't just doing this open source in the first place.
- tmarice 6mo agoA couple of years ago I had to evaluate A/B test and feature flag providers, and even then when they were a young company fresh out of YC, GrowthBook stood out. Bayesian methods, bring your own storage, and self-hosting instead of "Contact us for pricing" made them the go-to choice. I'm glad they're doing well.
- VadimPR 6mo agoThese security failures from Anthropic lately reveal the caveats of only using AI to write code - the safety an experienced engineer is not matched by an LLM just yet, even if the LLM can seemingly write code that is just as good. Or in short, if you give LLMs to the masses, they will produce code faster, but the quality overall will degrade. Microsoft, Amazon found out this quickly. Anthropic's QA process is better equipped to handle this, but cracks are still showing.
- squeegmeister 6mo agoAnthropic has a QA process? I run into bugs on the regular, even on the "stable" release channel
- FuckButtons 6mo agoTo a certain extent, I do wonder if just letting claude do everything and then using the bug reports and CVE’s they find as training data for an RL environment might be part of the plan. “Here’s what you did, here’s what fixed it, don’t fuck up like that again"
- therealarthur 6mo agoThink It's just the CLI Code right? Not the Model's underlying source. If so - not the WORST situation (still embarrassing)
- ZainRiz 6mo agoMaybe now someone will finally fix the bug that causes claude code to randomly scroll up all the way to the top!
- seifbenayed1992 6mo agoWent through the bundle.js. Found 187 spinner verbs. "Combobulating", "Discombobulating", and "Recombobulating". The full lifecycle is covered. Also "Flibbertigibbeting" and "Clauding". Someone had fun.
- ghrl 6mo agoLet's hope they left the having-fun part for a human to do.
- jakegmaths 6mo agoI think this is ultimately caused by a Bun bug which I reported, which means source maps are exposed in production: https://github.com/oven-sh/bun/issues/28001 https://github.com/oven-sh/bun/issues/28001 Claude code uses (and Anthropic owns) Bun, so my guess is they're doing a production build, expecting it not to output source maps, but it is.
- game_the0ry 6mo ago[flagged]
- lanbin 6mo agoOpen Claude Code? Better than OpenCode and Codex
- rurban 6mo agoNot really. This guy expresses my feelings: https://www.youtube.com/watch?v=nxB4M3GlcWQ https://www.youtube.com/watch?v=nxB4M3GlcWQ I also prefer codex over claude. But opencode is best. If you can use a good model. We can via Github Business Subscription.
- sandipb 6mo agoThe only issue I have with opencode is that it takes over the entire terminal, unlike claude code. Otherwise I love OC.
- arcanemachiner 6mo agoI wish. Claude Code is clearly a pile of vibe-coded garbage. The UI is janky and jumps all over the place, especially during longer sessions. (Which also have a several second delay to render. In a terminal). Lately, it's been crashing if I hold the Backspace key down for too long. Being open-source would be the best thing to happen to them. At least they would finally get a pair of human eyes looking at their codebase. Claude is amazing, but the people at Anthropic make some insane decisions, including trying (and failing, apparently) to keep Claude Code a closed-source application.
- tills13 6mo agoIs it not already a node app? So the only novel thing here is we know the original var names and structure? Sure, sometimes obfuscated code can be difficult to intuit, but any enterprising party could eventually do it -- especially with the help of an LLM.
- _ojxq 6mo agosource maps leaking original source happens surprisingly often. they're incredibly useful during development, but it's easy to forget to strip them from production builds.
- deleted 6mo ago[deleted]
- mmaunder 6mo agoThe only sensible response is to immediately open source it.
- mil22 6mo agoThis isn't even the first time - something similar happened back in February 2025 too: https://daveschumaker.net/digging-into-the-claude-code-source-saved-by-sublime-text/ https://daveschumaker.net/digging-into-the-claude-code-sourc... https://news.ycombinator.com/item?id=43173324 https://news.ycombinator.com/item?id=43173324
- djmips 6mo agoApparently a yearly ritual
- vanyaland 6mo agoThis leak is actually a massive win. Now the whole community can study Claude Code’s architecture and build even better coding agents and open-source solutions.
- dannersy 6mo agoThere is little of value in this code.
- DanDeBugger 6mo agoFascinating, it appears now anyone can be Claude! Though I wonder how the performance differs from creating your own thing vs using their servers...
- foob 6mo agoAmusingly, they deprecated it with a message of "Unpublished" instead of actually unpublishing it [1]. When you use npm unpublish it removes the package version from the registry, when you use npm deprecate it leaves it there and simply marks the package as deprecated with your message. I have to imagine the point was to make it harder for people to download the source map, so to deprecate it with this message gives off a bit of claude, unpublish the latest version of this package for me vibe. [1] - https://www.npmjs.com/package/@anthropic-ai/claude-code/v/2.1.88?activeTab=code https://www.npmjs.com/package/@anthropic-ai/claude-code/v/2....
- jaapz 6mo agoYou can say what you want about anthropic but they sure as hell are dogfooding the crap out of claude code lmao
- kami23 6mo agoIn all my years of writing tools for other devs, dog fooding is the really the best way to develop IMO. The annoying bugs get squashed out because I get frustrated with it in my flow. Iterating on a MCP tool while having Claude try to use it has been a really great way of getting it to work how others are going to use it coming in blind. Yes it's buggy as hell, but as someone echoed earlier if the tool works most of the time, a lot of people don't care. Moving fast and breaking things is the way in an arms race.
- danudey 6mo ago> In all my years of writing tools for other devs Not just tools for devs, this is true in a lot of cases. I used to work at Fortinet and every now and then we'd get an e-mail from information services letting us know that they would be installing a dev build of FortiOS on our internal (production) corporate network. In cases where we needed more debug logging from a feature or where we had a fix we had to test on a live network, and if we didn't want to ship a test firmware to some huge client and say 'here, see if this bricks your network or not', they would hand it off to our IT team and we'd install it on our own network to run. After all, if you're not confident enough to run it how can you be confident enough to ask your customers to run it? Now if they could just get the hang of not hard-coding admin credentials into the software they'd have a lot to brag about!
- solaire_oa 6mo agoI couldn't tell from the title whether is was client or the server code (although map file and NPM were hints). Looks like the client code, which is not as exciting.
- lanbin 6mo agoI read it with a different flavor. Is it possible that Mythos did all of this? I mean, life has always been finding a way, hasn't it? The first cry of cyber-life?
- nickvec 6mo agoAnd this is what happens when you don’t take security seriously folks and instead just rush out vibecoded features without proper QA.
- goworm 6mo ago[dead]
- deleted 6mo ago[deleted]
- meta-level 6mo agoThis is what I'd do to trick my competitors into thinking they now know my weak spots, agenda, etc.: drop a honeypot and do something else :)
- minimaltom 6mo agoThis 'fingerprint' function is super interesting, I imagine this is a signal they use to detect non-claude-code use of claude-code tokens: src/utils/fingerprint.ts#L40-L63
- mattlangston 6mo agoBoris Cherny has said that Claude Code is simply a client of the public Claude API, so this may be a good thing for Anthropic to demonstrate Claude API best practices. Maybe CC "leaking" is just preparation for open sourcing Claude Code.
- jmward01 6mo agoI hope this can now be audited better. I have doubted their feedback promises for a while now. I just got prompted again even though I have everything set to disable, which shouldn't be possible. When I dug into their code a long time ago on this it seemed like they were actually sending back message ids with the survey which directly went against their promise that they wouldn't use your messages. Why include a message id if you aren't somehow linking it back to a message? The code look, not great, but it should now be easier to verify their claims about privacy.
- philbitt 6mo ago[dead]
- blobbers 6mo agoIt's a little bit shocking that this zipfile is still available hours later. Could anyone in legal chime in on the legality of now 're-implementing' this type of system inside other products? Or even just having an AI look at the architecture and implement something else? It would seem given the source code that AI could clone something like this incredibly fast, and not waste it's time using ts as well. Any Legal GC type folks want to chime in on the legality of examining something like this? Or is it liked tainted goods you don't want to go near?
- evanbabaallos 6mo agoReleasing a massive feature every day has a cost! unreliability becomes inevitable!
- xyst 6mo agoBad day for the node/npm ecosystem.
- oxag3n 6mo agoMany comments about code quality being irrelevant. I'd agree if it was launch-and-forget scenario. But this code has to be maintained and expanded with new features. Things like lack of comments, dead code, meaningless variable names will result in more slop in future releases, more tokens to process this mess every time (like paying tech-debt results in better outcomes in emerging projects).
- alhirzel 6mo agoI love the symbol name: "AnalyticsMetadata_I_VERIFIED_THIS_IS_NOT_CODE_OR_FILEPATHS`.
- fatcullen 6mo agoThere's a bunch of unreleased features and update schedules in the source, cool to see. One neat one is the /buddy feature, an easter egg planned for release tomorrow for April fools. It's a little virtual pet, sort of like Tamagotchi, randomly generated with 18 species, rarities, stats, hats, custom eyes. The random generation algorithm is all in the code though, deterministic based on you account's UUID in your claude config, so it can be predicted. I threw together a little website here to let you check what your going to get ahead of time: https://claudebuddychecker.netlify.app/ https://claudebuddychecker.netlify.app/ Got a legendary ghost myself.
- dyz2102 6mo agoCongrats on the legendary, happy with my uncommon ghost, turned it into a holographic trading card via Gemini instead of ASCII. The stats bars and rarity colors are all derived from the UUID roll. Fun rabbit hole: https://github.com/dyz2102/buddy-card https://github.com/dyz2102/buddy-card
- fatcullen 6mo agoUpdate: it looks like the live version of the algorithm is slightly different, probably changed because of these leaks. As such the app predictions aren't accurate, sorry
- starkeeper 6mo agoIt should be open source anyways. Maybe they will change gears.
- bazmattaz 6mo agoI’m just curious, why do you think it should be open source. It’s a private company. The source code is their IP
- HDBaseT 6mo agoConsidering they "stole" everyone else's code for profit, it seems fair to at least contribute a bit back to the OSS Community. Claude Code being open source also allows for more advanced / custom tooling.
- animanoir 6mo ago[dead]
- dark-star 6mo agoThe more I think about this, the more it seems they're not talking about linker map files[1].... [1] https://www.tasking.com/documentation/smartcode/ctc/reference/listfmt_lk.html https://www.tasking.com/documentation/smartcode/ctc/referenc...
- sheeshkebab 6mo agoObfuscated ts/js code is not machine code to begin with, so not sure what’s the big deal. Also, not sure why anthropic doesn’t just make their cli open source - it’s not like it’s something special (Claude is, this cli thingy isn’t)
- petcat 6mo ago> not sure why anthropic doesn’t just make their cli open source They don't want everyone to see how poorly it's implemented and that the whole thing is a big fragile mess riddled with bugs. That's my experience anyway. For instance, just recently their little CLI -> browser oauth login flow was generating malformed URLs and URLs pointing to a localhost port instead of their real website.
- restlake 6mo agocaught that too a few weeks ago, couldn’t log in for a few hours either. I did a double take at the localhost when it loaded up in my browser haha
- nasretdinov 6mo agoI don't think you really need to look at the source code to understand that it's probably been, let's say, written with a heavy help from Claude itself
- tempest_ 6mo agoLook at the gemini-cli. Pretty sure it will look like that
- bpodgursky 6mo agoI really don't think they care that much, but it's a tight race and gives them a slight edge over other labs building harnesses, since they are in the lead.
- ramraj07 6mo agoBrowse through codex and think if anyone cares about the quality of the code before Open sourcing it.
- freakynit 6mo agotools/bashSecurity.ts is a hackers goldmine. Sooo many exploit patterns detailed in there!!
- randomsc 6mo agoDid it happen due to Bun?
- neilv 6mo agoI've never understood this convention (common on HN, some news orgs, and elsewhere), that, when there's an IP breach, it's suddenly fair game for everyone else to go through the IP, analyze and comment on it publicly, etc.
- feature20260213 6mo agoIt's because Anthropic doesn't care about IP
- neilv 6mo agoWhat I described is standard public behavior, regardless of the company.
- Uptrenda 6mo agoThat idea list is super cute. I like the tamagochi idea. Somehow the candidness of that file makes it seem like anthropic would be an easy place to work at.
- barazany 6mo agoI analyzed its compaction engine, 3-layer masterpiece of which I write in full here: https://barazany.dev/blog/claude-codes-compaction-engine https://barazany.dev/blog/claude-codes-compaction-engine
- theaicloser 6mo ago[flagged]
- scotty79 6mo agoIs this relevant? It's written in JS. LLMs are probably great in deobfuscation.
- Jaco07 6mo ago[dead]
- mmaunder 6mo agoIn the source there is an outbound-only Remote Control session that can forward recent transcript history and ongoing user/assistant/local-command events to a claude.ai session, likely for cross-device/session sync, remote viewing, internal dogfooding, or telemetry/ops experiments. It’s separate from the normal explicit /remote-control flow. But in the actual production binary I checked, the mirror helpers are compiled down to hard false, so it does not appear enabled in the shipped distribution build. Same story for the anti_distillation: ['fake_tools'] path: I could find it in source, but the prod binary I checked does not contain the anti_distillation / fake_tools strings at all.
- jascal 6mo ago[dead]
- shreyssh 6mo ago[flagged]
- jacquesm 6mo agoWho is we? There is absolutely no way I'm going to allow any kind of agent access to my file system, that sounds like a massive compliance nightmare besides the security implications.
- ozgurozkan999 6mo agoif I name my package as kairos cli would I violate anything?
- jrm4 6mo agoGood. While I don't condone anything illegal, influential code like this is nearly always better made public.
- airblackbox 6mo ago[dead]
- iheartbiggpus 6mo agoYikes, named staff in comments, jeez.
- wrkxapp 6mo agostop with the fake news dude im already sadded over 4o
- KnuthIsGod 6mo ago"They use Axios for HTTP, which is funny timing given that Axios was just compromised on npm with malicious versions dropping a remote access trojan."
- jaikechen 6mo agoisn't Claude Code too arrogant ?
- alexmarquez 6mo ago[dead]
- attentive 6mo agohttps://xcancel.com/altryne/status/2039005970865516955 https://xcancel.com/altryne/status/2039005970865516955 > Someone inside Anthropic, got switched to Adaptive reasoning mode > Their Claude Code switched to Sonnet > Committed the .map file of Claude Code > Effectively leaking the ENTIRE CC Source Code > @realsigridjin was tired after running 2 south korean hackathons in SF, saw the leak > Rules in Korea are different, he cloned the repo, went to sleep > Wakes up to 25K stars, and his GF begging him to take it down (she's a copyright lawyer) > Their team decided - how about we have agents rewrite this in Python!? Surely... this is more legal > Rewrite in Py > Board a plane to SK > One of the guys decides python is slow, is now rewriting ALL OF CLAUDE CODE into Rust. > Anthropic cannot take down, cannot sue > Is this "fair use?" > TL;DR - we're about to have open source Claude Code in Rust
- clankerbad 6mo agoYou know, I knew that frustration was detected because, well, duh, you can drop a single "shit" even somewhere where it isn't critical of the agent's work, and it becomes apologetic, lol. But I always thought that using the word "Clanker" was going to be one of the triggers. Turns out no. I guess Claudad is not up to the lingo.
- toniantunovi 6mo agoVery nice contribution to OSS
- pmakhija3 6mo ago[dead]
- socialawy 6mo ago[dead]
- socialawy 6mo ago[dead]
- deleted 6mo ago[deleted]
- mvizdos 6mo ago[dead]
- noritaka88 6mo ago[flagged]
- LZong 6mo agoBuilt the hooks-based version of this: github.com/LZong-tw/clawback Stop hook runs tsc + lint, exit 2 blocks completion. Same patterns, public API, no flags to hack.
- aimemobe 6mo ago[flagged]
- pukaworks 6mo ago[flagged]
- aimemobe 6mo ago[flagged]
- federico_baez 6mo ago[dead]