Claude Code source code accidentally leaked in NPM package
2026-04-01T01:23:28Z•22dd98fc31f61e787c632097e998e07bccfca4d189d38c1823da6c301dae89c4
AI-assisted-researchAxiosCISACiscoCitrixClaudeGIGABYTENetScalerRCERoadK1llTrivyarbitrary-file-writecredential-theftdata-breachhealthcare-breachimplantmalwarenpmpivotingremote-code-executionsource-code-leaksource-code-theftsupply-chain-compromise
What happened
Multiple high-impact security events and vulnerabilities were reported: Anthropic accidentally published closed-source Claude Code in an npm package (no customer credentials reported exposed); attackers compromised the popular Axios npm package to deliver cross‑platform RATs (npm supply‑chain compromise); Cisco had source code stolen after threat actors used credentials from the Trivy supply‑chain incident to breach a dev environment; researchers (using Claude) discovered file‑open RCE bugs in Vim and GNU Emacs; GIGABYTE Control Center contains an arbitrary file‑write flaw that can expose host
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 22dd98fc31f61e787c632097e998e07bccfca4d189d38c1823da6c301dae89c4
- Enrichment time
- 2026-04-01T01:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.