Skip to content
Artwork for Front-End Fire
Front-End Fire · April 6 · 36 min

139: Claude Code’s Secrets Are Out

This week, Anthropic accidentally leaked Claude Code’s source code to the world when it published a source map inside an npm release. While the offending file was quickly removed, the code was out there and folks got to work speculating about what’s next for Claude Code. Always running background daemons, something known as “undercover mode”, and a cute little ASCII animal next to inputs are some of the things we might see in Claude’s future. The npm hacks keep on coming as well, as popular data fetching library Axios is the latest victim. This particular hack delivered a remote access trojan (RAT) virus courtesy of a postinstall script, that deleted itself after execution to evade detection. Sneaky! Lock down your packages and dependencies, folks. Timestamps: 1:13 - Anthropic accidentally Claude Code’s source code 14:02 - Popular npm library Axios got hacked 23:40 - RedwoodSDK 1.0 28:28 - What’s making us happy News: Paige - Anthropic accidentally leaked Claude Code’s source code TJ - Popular npm library Axios got hacked Lightning News: RedwoodSDK 1.0 What Makes Us Happy this Week: Paige - The Idiot podcast from the New York Times TJ - Activate Games Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube. Front-end Fire website Blue Collar Coder on YouTube Blue Collar Coder on Discord Reach out via email Tweet at us on X @front_end_fire Follow us on Bluesky @front-end-fire.com Subscribe to our YouTube channel @Front-EndFirePodcast

0:00-36:29

transcript

No transcript — this publisher did not publish one.

show notes

This week, Anthropic accidentally leaked Claude Code’s source code to the world when it published a source map inside an npm release. While the offending file was quickly removed, the code was out there and folks got to work speculating about what’s next for Claude Code. Always running background daemons, something known as “undercover mode”, and a cute little ASCII animal next to inputs are some of the things we might see in Claude’s future.

The npm hacks keep on coming as well, as popular data fetching library Axios is the latest victim. This particular hack delivered a remote access trojan (RAT) virus courtesy of a postinstall script, that deleted itself after execution to evade detection. Sneaky! Lock down your packages and dependencies, folks.

Timestamps:

  • 1:13 - Anthropic accidentally Claude Code’s source code
  • 14:02 - Popular npm library Axios got hacked
  • 23:40 - RedwoodSDK 1.0
  • 28:28 - What’s making us happy

News:

Lightning News: 

What Makes Us Happy this Week:

Thanks as always to our sponsor, the Blue Collar Coder channel on YouTube. You can join us in our Discord channel, explore our website and reach us via email, or talk to us on X, Bluesky, or YouTube.

links11