PluginBench
MCP Server
Active

Claude Code Explorer MCP MCP Server

io.github.nirholas/claude-code-explorer-mcp

Historical documentation of the Claude Code source leak and its aftermath—not a functional MCP server.

What is the Claude Code Explorer MCP MCP server?

Claude Code Explorer MCP is not a functional server. This repository documents the March 2026 Claude Code source leak, its DMCA takedown, and corrections to misinformation about alleged cryptocurrency features. It contains no Anthropic source code and should not be installed or run.

This is a historical archive and reference documenting what happened during the Claude Code source leak, what was removed, and corrections to false claims about undocumented payment systems. It is not an MCP server and does not provide tools or capabilities. The README explicitly warns against running copies of the leaked codebase due to malicious package squatting and trojanized repositories.

How to install Claude Code Explorer MCP

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "claude-code-explorer-mcp": {
      "command": "node",
      "args": [
        "-y",
        "claude-code-explorer-mcp"
      ]
    }
  }
}

Claude Code Explorer MCP MCP server FAQ

Is this a working MCP server I can install?

No. This repository is a historical archive documenting the Claude Code source leak and its aftermath. It contains no functional MCP server code and should not be installed.

Does it contain Anthropic's Claude Code source?

No. All Anthropic source code was removed following a DMCA notice. The repository now serves only as a historical record of the leak and corrections to misinformation.

Why shouldn't I run this code?

The leaked codebase imports internal packages that do not exist on the public npm registry. Malicious packages with those exact names were published by squatters, and running `npm install` can execute arbitrary code. Additionally, trojanized 'Claude Code leak' repositories were documented distributing malware like Vidar and GhostSocks.

What does HISTORY.md explain?

HISTORY.md provides a complete record of what leaked, what the DMCA covered, and corrections to false claims—particularly that Claude Code never contained a cryptocurrency wallet or autonomous payment system, despite popular writeups claiming otherwise.

How can I verify claims about the x402 payment code?

The README provides three independent verification methods. Running `grep -r x402 src/` on any copy of the leak will show it was added by the repository owner after the leak, not part of Anthropic's original code.

Should I use the official Claude Code CLI instead?

Yes. Use the official Claude Code CLI from Anthropic rather than any leaked or third-party copies.

README (reference)

Source of truth, from the repository.

Fresh Start

This is the repository formerly known as nirholas/claude-code, the most widely forked mirror of the Claude Code source leak of 31 March 2026. It is the same repository object, so github.com/nirholas/claude-code still redirects here.

It contains no Anthropic source code, and it will not. The contents were removed after Anthropic's DMCA notice. That notice has not been retracted.

Read this instead

HISTORY.md is the full record: what leaked and how, what the DMCA did and did not cover, and the correction that still needs making.

The short version of the correction: Claude Code has never contained a cryptocurrency wallet or an autonomous payment system. The x402 payment code that circulated with copies of this leak was mine. I wrote it, on top of the leaked tree, while building a project of my own. It was not Anthropic's and it was not in the leak. Several popular writeups still report it as an undocumented Anthropic feature. HISTORY.md shows three independent ways to verify that it is not, and gives a complete accounting of every file I changed.

If you are auditing a copy of the leak you already hold, grep -r x402 src/ is the test.

Do not run copies of the leak

The leaked tree imports internal packages that do not exist on the public npm registry, and squatters publish malicious packages under exactly those names. Installing dependencies from any copy of this codebase can execute arbitrary code on your machine. There were also genuinely trojanized "Claude Code leak" repositories in circulation in April 2026, documented by Zscaler ThreatLabz, distributing Vidar and GhostSocks through a Windows executable. Use the official Claude Code CLI from Anthropic.

License

All rights reserved. See LICENSE.

Related MCP servers

Ask any website's AI concierge a grounded question, and embed one on your site.

218
JavaScript
Apache-2.0
View repository →

Manage copy-trading follows with AI: tune position sizing, guard rules, and track fees owed.

218
JavaScript
Apache-2.0
View repository →

Real-time crypto prices, OHLCV data, and DeFi market information via MCP for AI assistants.

27
TypeScript
View repository →

Central registry API for discovering and managing 800+ crypto, DeFi, and blockchain MCP tools with trust scoring.

24
TypeScript
View repository →

Pump.fun creator rewards, DexScreener pair search, crypto headlines, and USD candles.

View repository →

42 production-ready AI agent definitions for DeFi trading, portfolio management, and Web3 workflows via RESTful JSON API.

33
TypeScript
View repository →