Leak 2: @anthropic-ai/claude-agent-sdk Bundle (Mar 7, 2026)
- Entity ID:
ent-20260419-a002c3d4e5f6 - Type:
issue - Scope:
shared - Status:
active - Aliases: second leak, claude-agent-sdk leak, March 7 2026 leak, silent leak
Description
A distinct, previously under-documented leak via an entirely different npm package — @anthropic-ai/claude-agent-sdk — which shipped the entire Claude Code CLI bundle (cli.js, ~13,800 lines of minified JavaScript, version 2.1.71, built March 6, 2026). An executable file crossed into a different package from a different build pipeline. Silently fixed without public acknowledgment. Proves leak vector diversity: not a single misconfiguration.
Key claims
- Three leak vectors rule out single-misconfiguration explanation
Relations
- Three-Vector Leak Pattern --[contains]--> Leak 2: @anthropic-ai/claude-agent-sdk Bundle (Mar 7, 2026)