Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Two supply chain incidents converged within 48 hours to create compounding risk for organizations running Anthropic’s Claude Code npm package. The first incident, an Anthropic packaging error in v2.1.88, exposed approximately 512,000 lines of internal TypeScript source code via embedded source maps, disclosing internal architecture to any consumer of the package. The second and more severe incident involved a trojanized Axios HTTP client dependency, reportedly delivered through a hijacked npm maintainer account during a roughly three-hour window on March 31, 2026 (per T3 reports pending official confirmation); based on available reporting, developers who updated Claude Code during that window may have received a cross-platform remote access trojan, giving attackers potential persistent access to build environments, credentials, and potentially production secrets. **Severity Note:** All current sources are T3 (secondary news and community reports). Details are subject to change pending official Anthropic and Axios maintainer security advisories.

Author

Tech Jacks Solutions