Imagine shipping your company's entire source code to the public. No breach, no hacker. Just one missing file.
That's what happened on March 31, 2026, when Claude Code version 2.1.88 went out to npm with a 59.8 MB source map. 512,000 lines of readable TypeScript. Within hours, it was forked over 41,500 times.
The cause: no .npmignore file and no "files" whitelist in package.json. So npm shipped everything.
"Plain developer error." Which is exactly why it matters. It can happen to anyone.
Profero question: when did someone last check what your published packages actually contain? 👀
How to check if you're exposed is in the first comment>>>