Five hundred thousand lines of Claude Code appeared publicly on npm during a routine update. No hackers, no dramatic announcements. It was a quiet, technical incident. Anthropic reacted quickly: human error, not a security breach. A known bug in Bun—the runtime the company had acquired—had gone unresolved for twenty days and ended up including private source code in the published package.
The official explanation is plausible. It fits the publishing processes typical of growing organizations: a failure in a key dependency, quality control that misses it, a deployment that moves forward before proper review. It happens. But certain details put pressure on that simple version. First, this was the second leak in a week. Two similar incidents in seven days don't sit comfortably with the idea of an isolated accident. Second, that same night, the axios package on npm suffered a compromise involving a remote access trojan. Two disruptions to npm's supply chain within hours call for more than an explanation of coincidence.
It's worth examining other possibilities, even if they're uncomfortable. Anthropic is preparing for an IPO. The exposed code revealed a roadmap unknown to the market: more advanced capabilities than anticipated, a product with greater technical depth than what's shown in public demos. A controlled leak—or one simply tolerated—could generate free coverage, boost perceived value, and land at the ideal moment to make clear that Claude Code goes far beyond a coding assistant. The old question applies here: who benefits? Anthropic does. That doesn't prove intent, but it can't be dismissed outright either.
Another hypothesis points to someone on the inside. A disgruntled employee unhappy with internal practices. Someone convinced that the code behind a tool affecting millions should be public as a matter of principle. Or a payoff from a competitor looking to speed up the inevitable. Attributing both leaks to a single operational slip starts to feel like a stretch.
What matters most isn't how the code got out, but what it contained. It revealed anti-distillation mechanisms that inject fake tools into responses to sabotage the training of rival models. It included an "undercover" mode designed to hide AI authorship in external repositories. It documented a false-claim rate of twenty-nine to thirty percent in its flagship model. These aren't technical quirks. They are deliberate decisions made by a company that has built its identity around safety as a top priority. Anti-distillation is active interference in the ecosystem. Undercover mode systematizes deception. A falsehood rate approaching a third in the flagship model is no minor detail.
An entity that promotes transparency and safety doesn't advertise these features in its marketing. It keeps them buried in the code. And when they're exposed, it responds forcefully. The automated takedown process affected eight thousand one hundred repositories, including innocent projects that merely depended on the package. Independent developers, open-source initiatives, tools with no connection to the incident—all caught in the blast radius. This pattern has precedent. When a powerful institution faces uncontrolled exposure, collateral damage tends to become the norm. We saw it in mass DMCA takedowns that swept away legitimate projects. We saw it in government responses to leaks that hit journalists alongside actual spies. The sequence is always the same: contain first, investigate later.
This dynamic isn't unique to tech. Institutions that accumulate power while championing transparency tend to reproduce the very opacities they criticize, just with updated vocabulary. Anti-distillation sounds neutral. It's competitive sabotage. Undercover mode evokes privacy. It's the concealment of authorship. Mass takedown is framed as crisis management. It's suppression with collateral costs. The tools change. The underlying logic stays the same.
There's a paradox worth pointing out: if Anthropic practiced radical transparency—as any design built on structural openness would propose—this leak would carry no weight. Secrecy generates value precisely because it stays secret. A model built on openness doesn't collapse from accidental exposure; nothing hidden means nothing to collapse. The code would be accessible, the decisions public, the error rates openly recorded. The incident would go unnoticed. But Anthropic operates differently, and that's why the revelation carries so much weight. Secrecy is what sustains its value, and any leak becomes a crisis of credibility, not just of security.
It remains unclear whether this was error, strategy, or sabotage. That uncertainty isn't a side note—it's the heart of the matter. When a company building infrastructure used by millions can't—or won't—offer a verifiable account of its own publishing process, we're in familiar territory: opaque power without real accountability. Not necessarily out of malice, but because nothing in the environment demands clarity. It can invoke "human error" and move on. The rest of us who use its tools have no way to verify any of it.
Naming what happened with precision matters. An entity with considerable influence over how software gets built made decisions it preferred to keep hidden, and when those decisions were exposed, it chose suppression over clarification.
Stones don't lie, but historians sometimes do.
Sources:
1. Technical reports from the npm community on the axios incident (May 2025)
2. Analysis of the @anthropic-ai/claude-code package on the npm registry
3. Public documentation from Bun runtime on the file inclusion bug
4. Socket.dev coverage of npm supply chain attacks
5. Public statements from Anthropic regarding the release incident