Claude Code source code accidentally leaked in NPM package

2026-04-01T01:23:28Z22dd98fc31f61e787c632097e998e07bccfca4d189d38c1823da6c301dae89c4
AI-assisted-researchAxiosCISACiscoCitrixClaudeGIGABYTENetScalerRCERoadK1llTrivyarbitrary-file-writecredential-theftdata-breachhealthcare-breachimplantmalwarenpmpivotingremote-code-executionsource-code-leaksource-code-theftsupply-chain-compromise

What happened

Multiple high-impact security events and vulnerabilities were reported: Anthropic accidentally published closed-source Claude Code in an npm package (no customer credentials reported exposed); attackers compromised the popular Axios npm package to deliver cross‑platform RATs (npm supply‑chain compromise); Cisco had source code stolen after threat actors used credentials from the Trivy supply‑chain incident to breach a dev environment; researchers (using Claude) discovered file‑open RCE bugs in Vim and GNU Emacs; GIGABYTE Control Center contains an arbitrary file‑write flaw that can expose host

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
22dd98fc31f61e787c632097e998e07bccfca4d189d38c1823da6c301dae89c4
Enrichment time
2026-04-01T01:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.