Leak 2: @anthropic-ai/claude-agent-sdk Bundle (Mar 7, 2026)

Description

A distinct, previously under-documented leak via an entirely different npm package — @anthropic-ai/claude-agent-sdk — which shipped the entire Claude Code CLI bundle (cli.js, ~13,800 lines of minified JavaScript, version 2.1.71, built March 6, 2026). An executable file crossed into a different package from a different build pipeline. Silently fixed without public acknowledgment. Proves leak vector diversity: not a single misconfiguration.

Key claims

Relations

Sources

src-20260409-1ef27ff0b214