Anthropic's 500k lines of Claude Code Exposed via Missing Exclusion Rule

Anthropic unintentionally exposed over 500,000 lines of Claude Code, shipped inside their own npm package. Yes you heard it right, 500,000 lines of Claude Code. It wasn’t a breach. It was a release. A routine update included a 60MB debug artifact that should never have been there. Inside it: a significant portion of their internal codebase. Within hours: • Thousands of forks appeared across GitHub • The code spread faster than it could be contained • Takedown requests followed, but the damage was already done. This wasn’t the result of a sophisticated attack. It came down to something far more common and far more dangerous: • A missing exclusion rule in the package configuration. • A manual deployment step where automation should have existed. The kind of oversight most teams assume “won’t happen to us.” Boris Cherny, who led Claude Code’s growth into a multi-billion dollar product, addressed it directly: “The system failed, not the person.” No deflection. No noise. Just accountability and a focus on fixing the process. Because at scale, it’s rarely a single mistake that breaks things. It’s the absence of safeguards that were supposed to catch it. #softwareengineering #devops #security #buildinpublic #claudecode

To view or add a comment, sign in

Explore content categories