
Agents Hour Anthropic Leaked Their Own Source Code, OpenAI Raised $122b, and Axios Got Hacked (This Week In AI)
Shane and Abhi bring you your weekly roundup of AI news! Claude Code's entire source code leaked via an exposed .map file in npm — 512,000 lines of TypeScript, 50K GitHub stars before DMCAs started flying. What people found: Claude Code uses ~20 tools, and there's a regex that silently logs user frustration to analytics. Same week, a CMS misconfiguration exposed a draft blog post revealing Mythos and Capybara — a new model tier above Opus described as posing "unprecedented cybersecurity risks." Fortune separately confirmed a source saying Opus 5 is "so good it poses a danger."
Claude Code auto mode shipped — a classifier between constant interrupts and the skip-permissions flag. Computer use landed in Claude Code too, letting it open apps and click through UI from the CLI. Rate limits were tightened during peak hours to community backlash. A federal judge blocked the Pentagon's attempt to label Anthropic a supply chain risk.
A North Korea-linked group hijacked the npm account of Axios' lead maintainer and published malicious versions that stole env variables then cleaned up after themselves. With ~100M weekly downloads and Claude Code depending on Axios, the blast radius was significant. An Anthropic researcher also demoed Claude finding a zero-day in Ghost in 90 minutes. Agents are the new hackers, and the hackers have agents too.
OpenAI closed $122B at an $852B valuation. Sora is shutting down. Mistral raised $830M for an NVIDIA-powered EU data center. Redpoint's 2026 market update argues this isn't the dot-com bubble, while noting agent maturity is early, and incumbents face a structural disadvantage against AI-native startups.
Rapid fire: Gemini 3.1 Flash Live, Veo 3.1 Lite, pg-micro, Cloudflare runs Kimi K2.5, OpenCode remote sandboxes, Chroma 20B search agent, Cohere open-source transcription, Linear says issue tracking is dead, Microsoft M365 council mode, Mario Zechner's "Slow the fuck down," GLM-5.1, Google Translate live in headphones.
AI Agents Hour is a weekly livestream by Mastra CPO Shane Thomas and CTO Abhi Aiyer. Mondays 12PM Pacific.
📚 READ MORE
Claude Code leak: https://x.com/fried_rice/status/2038894956459290963
Frustration tracking: https://x.com/rahatcodes/status/2038995503141065145
Axios attack: https://x.com/mvxvvll/status/2038797094861918332
Claude zero-day: https://x.com/chiefofautism/status/2037951563931500669
OpenAI $122B: https://x.com/sawyermerritt/status/2039073153922539901
Sora shutdown: https://x.com/soraofficialapp/status/2036546752535470382
Auto mode: https://x.com/claudeai/status/2036503582166393240
Computer use in Code: https://x.com/claudeai/status/2038663014098899416
Mythos/Capybara: https://x.com/testingcatalog/status/2037394888577216617
Opus 5 danger: https://x.com/kimmonismus/status/2037461154088296748
Rate limits: https://x.com/trq212/status/2037254607001559305
Pentagon ruling: https://www.cnn.com/2026/03/26/business/anthropic-pentagon-injunction-supply-chain-risk
Mistral $830M: https://x.com/ft/status/2038531872272040374
Redpoint market update: https://www.redpoint.com/reports/2026-market-update/
Gemini 3.1 Flash Live: https://x.com/officiallogank/status/2037187750005240307
pg-micro: https://x.com/glcst/status/2037254698898432278
OpenCode sandboxes: https://x.com/jlongster/status/2036924361379037224
Linear: https://x.com/linear/status/2036502198062821842
📚 MASTRA RESOURCES
Mastra: https://mastra.ai
Mastra on X: https://x.com/mastra_ai
Mastra Discord: https://mastra.ai/community/discord
Mastra GitHub: https://github.com/mastra-ai
Learn Mastra in the world's first MCP-Based Course: https://mastra.ai/course
Principles of Building AI Agents (Book): https://mastra.ai/books/principles-of-building-ai-agents
Patterns for Building AI Agents (New Book): https://mastra.ai/books/patterns-of-building-ai-agents
MASTRA?
Mastra is an open-source TypeScript framework designed for building and shipping AI-powered applications and agents with minimal friction. It supports the full lifecycle of agent development—from prototype to production. You can integrate it with frontend and backend stacks (e.g., React, Next.js, Node) or run agents as standalone services. If you're a JavaScript or TypeScript developer looking to build an agentic or AI-powered product without starting from first principles, Mastra provides the scaffolding, tools, and integrations to accelerate that process.
00:00 — Claude Code source code leaked
04:30 — Axios supply chain attack
06:11 — Claude finds a zero-day in Ghost in 90 minutes
06:50 — OpenAI closes $122B round at $852B valuation
08:24 — Sora is shutting down
11:03 — Anthropic ships: auto mode & computer use in Claude Code
11:41 — Mythos & Capybara: Anthropic's next model tier leaked
14:35 — Claude rate limits tightened during peak hours
15:51 — Judge blocks Pentagon's supply chain risk label on Anthropic
16:08 — Mistral $830M & Redpoint's 2026 AI market update
20:45 — Rapid fire: Google, pg-micro, OpenCode, Chroma, Cohere & more
