Executive Summary
A major security incident unfolded as Claude Code and OpenAI Codex source code were leaked via exposed sourcemaps, triggering widespread community forking and analysis. Simultaneously, a critical npm supply chain attack targeted axios (300M weekly downloads), highlighting persistent vulnerabilities in package management ecosystems. On the innovation front, Ollama integrated Apple's MLX framework for significant Apple silicon performance gains, while Hermes Agent emerged as a compelling open-source alternative to OpenClaw with rapid feature development and multi-agent capabilities.
Key Events
-
Claude Code Source Code Leaked: Anthropic's Claude Code source code exposed via sourcemaps, forked thousands of times within hours, revealing ~512K lines of code and hidden features → tweet
-
npm axios Supply Chain Attack: Critical supply chain attack on axios package with 300M weekly downloads; users warned not to run npm install without lockfiles → tweet
-
Ollama Adds MLX Backend: Ollama now runs on Apple's MLX framework, unlocking 2.2x speed improvements on models like Qwen 3.5:36b on Apple silicon → tweet
-
Hermes Agent Multi-Agent Profiles Released: Open-source agent framework adds multi-agent profiles, same-day PR merges, and active community development → tweet
-
MiniMax M2.7 Open Sourced: Model released open source directly from the MiniMax team → tweet
-
Transformers.js v4 Released: New WebGPU backend for browser and Node.js ML inference → tweet
-
OpenAI Codex Codebase Also Leaked: Second major proprietary codebase leak reported → tweet
Analysis
Patterns: The dual source code leaks (Claude Code and Codex) within the same 24-hour window reveal persistent security hygiene issues around sourcemap exposure in production builds. The axios supply chain attack reinforces that npm/JavaScript ecosystems remain high-value targets for attackers.
Escalation: Tension between open-source advocates and proprietary AI companies is intensifying. Anthropic's previous DMCA takedowns are being widely discussed as ironic given the leak. Hermes Agent is positioning itself as the open, community-driven alternative to Closed/commercial agent tools.
What to Watch: - Anthropic's response to Claude Code leak (DMCAs expected) - Community forks and rewrites of Claude Code functionality in open source - Hermes Agent adoption momentum vs OpenClaw - Nvidia vs Alibaba Qwen model performance on datacenter hardware (2x H200 benchmarks ongoing)
Tweet Feed
Claude Code / Codex Source Leaks
@TheAhmadOsman · 2026-03-31T18:30
thank you for leaking the Claude Code source code to the opensource community this time Dario 💙 https://t.co/GVzD55t6Nh → tweet
@TheAhmadOsman · 2026-03-31T17:47
Opensource is Anthropic's Lord Voldemort
336 days ago Anthropic's sent me a DMCA takedown for my opensource fork of Claude Code
today Claude Code source code got leaked and is cloned and forked 10000s of times lol → tweet
@jezell · 2026-03-31T09:09
Claude Code just got open sourced by sourcemaps 😂.
The larger question is why in the world is Claude Code not open source like Codex is? Even their fake repo with some plugins doesn't use an open source license. Not to be trusted greedy lawyered up company wants to be the next Oracle. → tweet
@thdxr · 2026-03-31T12:31
claude code source is 512K lines opencode is 118K
we're getting LOC mogged → tweet
@steipete · 2026-03-31T18:12
this just became more relevant 🙃 → tweet
@steipete · 2026-03-31T16:40
RT @reach_vb: holy shitt, somebody at OpenAI leaked the entire codex codebase.. → tweet
npm Supply Chain Attack
@karpathy · 2026-03-31T05:23
New supply chain attack this time for npm axios, the most popular HTTP client library with 300M weekly downloads.
Scanning my system I found a use imported from googleworkspace/cli from a few days ago when I was experimenting with gmail/gcal cli... → tweet
@nummanali · 2026-03-31T06:17
Axios from the JavaScript ecosystem has been comprised - more than 300M weekly downloads
Do not run ANY npm install commands without a lock file
At this point we need to deeply rethink security for package managers → tweet
@alexinexxx · 2026-03-31T12:09
in one week
npm axios attack claude code leak FBI director's gmail hacked
great time to be in security rn → tweet
Hermes Agent / Open Source AI Tools
@Teknium · 2026-03-31T01:18
Multi Agent Profiles is finally here 🤗 → tweet
@Teknium · 2026-03-31T02:12
Got tool call streaming working in OpenWebUI with our openai endpoint for Hermes Agent!
So badass! Get the bleeding edge feature update with a simple
hermes updatein your console! → tweet
@sudoingX · 2026-03-31T09:23
some bloat agent devs block you for pointing out bugs. hermes agent merges your fix the same day.
third PR, third same-day merge. reported the bug in teknium's thread this morning and opened the fix, tested on a live 3090, merged by afternoon.
this is what local-first open source looks like when the people building it actually care about the people using it. → tweet
@Teknium · 2026-03-31T03:43
A full straightforward tutorial on setting up Hermes Agent! Give it a watch especially if coming to hermes agent fresh! → tweet
Ollama / MLX / Local Inference
@ollama · 2026-03-31T04:27
Ollama is now updated to run the fastest on Apple silicon, powered by MLX, Apple's machine learning framework.
This change unlocks much faster performance to accelerate demanding work on macOS → tweet
@sudoingX · 2026-03-31T08:26
hey if you're setting up hermes agent with a local model for the first time, i just opened my third PR to make it easier.
when you point hermes agent at your local server during setup it now probes the endpoint and auto-detects your model. → tweet
AI Model Releases & Benchmarks
@TheAhmadOsman · 2026-03-31T01:49
You see how I am smiling? It's because I knew MiniMax-M2.7 was going to be opensourced directly from their team during GTC week 😄 → tweet
@sudoingX · 2026-03-31T12:33
the past week i've been publishing head to head tests between nvidia vs alibaba AI models on consumer hardware like RTX 3090. same GPU, same tests, same inference engine. letting the architectures fight.
nvidia failed twice on my 3090...
so i'm done with consumer hardware for this fight. loading both flagships on 2x H200 NVL. 287GB of VRAM. → tweet
@TheAhmadOsman · 2026-03-30T22:17
Current models rotation (mix of API & local)
GPT 5.4 Pro (Subscription) MiniMax M2.7 (API) / M2.5 (local) GLM 5.1 (API) / 4.7 (local) Kimi K2.5 Qwen 3.5 397B MoE Qwen 3.5 27B Dense → tweet
@Ex0byt · 2026-03-30T21:21
qwen3.6-plus is available on OpenRouter as a free preview, stronger reasoning and more stable agentic tool calling → tweet
@victormustar · 2026-03-31T15:48
nice, granite is underrated 👀 → tweet
Developer Tools & Libraries
@steipete · 2026-03-31T16:36
New CodexBar beta has experimental multi-acount support for codex. → tweet
@victormustar · 2026-03-31T07:27
Featured Apps you can try on Hugging Face this week 🔥
🗣️ Voxtral TTS Demo: Mistral's new text-to-speech 🎙️ Cohere Multilingual ASR: multilingual transcription ⚡ Cohere WebGPU: same but locally in your browser 🎩 Mr. Chatterbox: Victorian-era gentleman chatbot → tweet
@jsuarez · 2026-03-31T12:13
I was pretty bummed that I didn't get to do as much science on RL scaling as I wanted in 4.0 because of how much time I spent on improving perf. Michael apparently did it though! This looks like it hooks in ideas from the original OAI RL scaling papers... → tweet
@victormustar · 2026-03-31T17:00
🚨 We can download models, but not see how they were built. Introducing daVinci-LLM: most transparent LLM pretraining project → tweet
GPU Hardware & Local AI
@sudoingX · 2026-03-31T12:59
people keep asking me about DGX Spark, DGX Station, which local hardware to choose. i get these in DMs, comments, replies daily.
i don't recommend what i haven't tested. the moment i have the hardware in front of me you'll get the same real data i publish for everything else. → tweet
@TheAhmadOsman · 2026-03-31T05:42
I owe so much to the RTX 3090s → tweet
@TheAhmadOsman · 2026-03-30T23:25
unboxing new GPUs feels like this https://t.co/TKthdcQrLL → tweet
Research & Open Source Projects
@jsuarez · 2026-03-31T16:55
You really can't hate Schmidhuber. Both my first paper and our upcoming Puffer 4 release heavily rely on a trick from one of his now mostly forgotten papers. → tweet
@alexinexxx · 2026-03-31T17:08
RT @vikhyatk: someone from AI2 accidentally leaked olmo training code on github → tweet
@badlogicgames · 2026-03-31T07:01
RT @yuvadm: if you