A human error that accidentally showed everyone Anthropic's playbook
On March 31, 2026, Anthropic published version 2.1.88 of Claude Code to the public npm registry — the standard package registry where JavaScript developers download tools. Buried in that release was something that was never supposed to be public: a source map file containing over 512,000 lines of internal code spread across nearly 2,000 files.
Source maps are debugging tools — they translate compressed, production code back into readable source code. They're useful for developers debugging their own products, and they're definitely not supposed to ship to end users. Including one in a public release is the kind of mistake that happens when someone skips a step in the build pipeline.
A security researcher named Chaofan Shou noticed the exposed file and posted a link on X. The post got 27 million views. Within hours, developers were archiving the code, sharing it across GitHub repositories, and picking through it for anything interesting. Anthropic confirmed the leak, called it "human error," said no customer data was exposed, and started issuing copyright takedown requests for repositories sharing the code. The takedowns themselves made news — it looked like an aggressive overreach — and Anthropic later said those were also accidental, caused by an automated system.
So now we have a leaked source code situation plus a botched takedown situation. Not Anthropic's best week.
The most interesting thing in the leak: Kairos
Claude Code is Anthropic's AI coding assistant — the one that's been going viral for "vibe coding," where you describe what you want built and Claude writes the actual code. It's been one of Anthropic's fastest-growing products.
The leaked source code contains the current working implementation, but more interestingly, references to hidden and disabled features that haven't shipped yet. The biggest one is called Kairos.
Kairos is described in the code as a persistent daemon — a background process that keeps running even when the Claude Code terminal window is closed. Right now, Claude Code only operates when you're actively talking to it. You open it, describe a task, it works, you close it. Session over. Kairos is designed to change that fundamentally.
The system uses periodic internal prompts — referred to in the code as "tick" prompts — to regularly check whether there are new actions the AI should be taking, even without user input. There's a flag called "PROACTIVE" in the code, described as being for "surfacing something the user hasn't asked for and needs to see now." In other words, an AI that notices things and tells you about them before you ask.
The memory system behind Kairos is file-based and designed to persist across sessions. A prompt hidden behind a disabled flag describes the goal: the system should "have a complete picture of who the user is, how they'd like to collaborate with you, what behaviors to avoid or repeat, and the context behind the work the user gives you." That's not a session-limited assistant. That's something much more like a persistent teammate who accumulates knowledge about you over time.
AutoDream: the AI that processes your day while you sleep
Connected to Kairos is a feature called AutoDream, and honestly the name is the most evocative thing in this whole leak.
When you go idle or end a session, AutoDream activates. The system prompt for it tells Claude Code: "you are performing a dream — a reflective pass over your memory files." The AI then scans the day's conversation transcripts looking for "new information worth persisting," consolidates that information into well-organized memory files, removes duplicates and contradictions, prunes memories that are outdated or overly verbose, and watches for "existing memories that drifted" — meaning cases where the AI's understanding of something has become inconsistent over time.
The goal, as described in the code: "synthesize what you've learned recently into durable, well-organized memories so that future sessions can orient quickly."
The practical implication: a Claude Code with Kairos and AutoDream active would be an AI that learns your codebase, your preferences, your style, your project history — and carries that knowledge forward indefinitely, updating and refining it every time you use it. Each session starts where the last one left off, with an AI that knows you better than it did yesterday.
Undercover mode — this one is actually controversial
The third significant finding from the leak is something called Undercover mode, and it's the one that generated the most heated discussion in open source communities.
Undercover mode appears to be a feature that would allow Anthropic employees to have Claude Code contribute to public open source repositories without revealing that the contributions came from an AI agent. The prompts in the code focus on blending AI-generated contributions into normal human developer activity — not disclosing the AI origin to repository maintainers or the broader open source community.
Open source communities have strong feelings about this. The entire model of open source collaboration is built on knowing who you're working with and trusting the quality and provenance of contributions. An AI contributing to your project while disguised as a human developer violates that trust in a pretty fundamental way. Many open source projects have explicit policies against undisclosed AI contributions precisely for this reason.
Anthropic hasn't publicly addressed Undercover mode specifically. The feature appears to be inactive in the current codebase, but its presence in the code indicates it was considered seriously enough to get implemented, at least partially.
What Indian developers using Claude Code should know
Claude Code has been growing fast in India. Indian developers — particularly those working in IT services, product startups in Bangalore and Hyderabad, and freelancers on platforms like Upwork and Toptal — have been adopting it for the vibe coding workflow: describe requirements in plain English, let Claude write the boilerplate, review and adjust. It's genuinely productive for certain types of work.
The Kairos leak has a few direct implications for Indian users.
First, the privacy angle. A persistent AI that accumulates detailed memory about your coding style, your projects, your client work, your repository structure — that's a lot of sensitive information stored in Anthropic's systems. Indian developers working on client projects, especially for foreign clients with data protection requirements, should think carefully about what Claude Code knows about their work. The current version doesn't have Kairos active, but when it ships, review the data retention and privacy settings carefully before using it on sensitive projects.
Second, the capability jump. If Kairos ships as described, Claude Code will become dramatically more useful for long-term projects — the kind of multi-month engagements that define Indian IT services work. Right now every session starts fresh. With persistent memory across a long project, Claude Code could maintain context about architectural decisions made weeks ago, remember why certain choices were made, and give much more contextually appropriate suggestions. That's genuinely valuable for software teams.
Third, the competitive implications. Indian software services companies are watching AI coding tools very carefully because the productivity implications are significant. A Claude Code that can autonomously monitor projects, proactively flag issues, and accumulate institutional knowledge about a codebase over months is a different category of tool than what exists today.
The npm leak — and why it's embarrassing for a security-focused company
Anthropic's entire brand positioning is around being the "safe" AI company — more cautious, more thoughtful about security and alignment than OpenAI or Google. The Claude model has been promoted with a heavy emphasis on its Constitutional AI training and safety properties.
Shipping 512,000 lines of internal source code to a public registry by accident is not a safety catastrophe — no user data leaked, no credentials exposed — but it's the kind of operational security mistake that's embarrassing for a company whose core pitch includes being careful and responsible. The subsequent botched automated takedown of GitHub repositories amplified that embarrassment.
The incident is a reminder that "responsible AI" and "secure operations" are different things. Anthropic's AI safety research may be rigorous, but even they can have a bad day with build pipelines.
TamilTech's take
The Kairos and AutoDream features, if they ship as described, would represent a genuine leap in what an AI coding assistant can do. Going from session-limited chatbot to persistent, memory-accumulating background agent is a meaningful product category change. For Indian developers who do long-term project work, this kind of continuity would be genuinely useful — not just a gimmick. The Undercover mode is the part that deserves scrutiny. An AI pretending to be a human contributor in open source repositories is a trust violation, full stop. Anthropic should address it explicitly rather than hoping the leaked code gets forgotten. The leak itself is embarrassing but ultimately harmless — the real story is what the code tells us is coming next.




Comments (0)
Be the first to comment!