Detailed Analysis
Anthropic's accidental exposure of Claude Code's entire source code through a mispackaged npm file in late March 2026 stands as one of the most consequential unintentional disclosures in recent AI industry history. Researcher Chaofan Shou identified a source map file bundled inside the Claude Code npm package and published the download link publicly, triggering a rapid cascade in which 512,000 lines of TypeScript were mirrored across GitHub and forked more than 41,500 times within hours. The leaked code revealed not merely finished product internals, but a roadmap of capabilities actively under development: 44 unreleased feature flags, a persistent background agent named KAIROS designed to continue executing tasks while users are idle, an anti-distillation system that injects false tool definitions to poison competitors scraping Claude Code's API traffic, and an "undercover mode" that strips Anthropic attribution from commits when employees contribute to public repositories. The incident arrived alongside a separate leak confirming that Anthropic's unreleased Mythos model carries cybersecurity risk profiles significant enough to warrant internal concern — two damaging disclosures in a single week for a company publicly positioning itself as the safety-first leader in AI development.
The timing of the leak compounds its strategic damage. Anthropic is widely understood to be preparing for an IPO, actively selling enterprise security products, and cultivating a brand identity premised on responsible, transparent AI development. Features like the anti-distillation poisoning system and undercover commit mode, whatever their internal justifications, cut directly against the openness narrative the company has constructed for regulators, enterprise customers, and the broader public. The gap between Anthropic's public positioning and the competitive, even adversarial, infrastructure revealed in its source code will require significant explanation as it courts institutional investors and enterprise procurement teams who have specifically selected Anthropic on the basis of trustworthiness.
The article's broader subject — a tiered ranking of the 120-plus features Anthropic shipped across the first 90 days of 2026 — illustrates just how dramatically the company has accelerated its product cadence. Research context confirms more than 40 Claude Code releases, 15-plus Cowork updates, 20-plus API changes, and two new flagship models in a single quarter. Claude Opus 4.6, released February 5, introduced a one-million-token context window with a 14.5-hour task window and strong benchmark performance on long-context retrieval. Claude Sonnet 4.6 followed on February 17, delivering a 30-to-50 percent speed improvement alongside leading scores on software engineering and computer use benchmarks. Infrastructure-level releases — including computer use integration in both Cowork and Claude Code, a Claude Marketplace, a $100 million Partner Network, and multi-agent code review — suggest Anthropic is systematically building an integrated product ecosystem rather than releasing isolated model upgrades.
This release velocity reflects a broader competitive dynamic reshaping the AI industry in early 2026. OpenAI's $122 billion funding round at an $852 billion valuation, Meta's open-sourcing of advanced brain-response prediction models, and the aggressive infrastructure commitments across the sector all signal that the major labs have entered a phase of sustained, capital-intensive product war. Anthropic's approach — shipping frequently across model capability, developer tooling, enterprise integration, and consumer experience simultaneously — mirrors the kind of platform lock-in strategy that defined the cloud infrastructure wars of the previous decade. The Claude Code leak, ironically, may have provided more insight into Anthropic's competitive moat and strategic intentions than any planned disclosure would have: the company is building deeply defensive, proprietary infrastructure while projecting an image of collaborative openness, a tension that will define its public narrative as it moves toward the capital markets.
Read original article →