
Security News
Anthropic Identifies Biased Reasoning and Recklessness as Drivers of Claude’s PyPI Attack
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.
@anthropic-ai/sdk
Advanced tools
The Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications.
Full documentation is available at platform.claude.com/docs/en/api/sdks/typescript.
npm install @anthropic-ai/sdk
import Anthropic from '@anthropic-ai/sdk';
const client = new Anthropic({
apiKey: process.env['ANTHROPIC_API_KEY'], // This is the default and can be omitted
});
const message = await client.messages.create({
max_tokens: 1024,
messages: [{ role: 'user', content: 'Hello, Claude' }],
model: 'claude-opus-4-6',
});
console.log(message.content);
TypeScript >= 5.0 is supported.
The following runtimes are supported:
"node" environment ("jsdom" is not supported at this time).dangerouslyAllowBrowser to true.Note that React Native is not supported at this time.
If you are interested in other runtime environments, please open or upvote an issue.
See CONTRIBUTING.md.
This project is licensed under the MIT License. See the LICENSE file for details.
FAQs
The official TypeScript library for the Anthropic API
The npm package @anthropic-ai/sdk receives a total of 22,259,276 weekly downloads. As such, @anthropic-ai/sdk popularity was classified as popular.
We found that @anthropic-ai/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 13 open source maintainers collaborating on the project.

Security News
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.

Research
/Security News
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.