
Security News
November CVEs Fell 25% YoY, Driven by Slowdowns at Major CNAs
November CVE publications fell 25% YoY even as 2025 totals rose, showing how a few major CNAs can swing “global” counts and skew perceived risk.
@trezor/connect-webextension
Advanced tools
High-level javascript interface for Trezor hardware wallet in webextension serviceworker environment.
This package contains @trezor/connect implementation suitable for webextensions. In short it:
This package is currently in beta. If you find anything not working or not suiting your needs, please open an issue.
At the moment only bundles build/trezor-connect-webextension.js and build/trezor-connect-webextension.min.js are published.
One way how it can be used is
importScripts('<path>/trezor-connect-webextension.js');
There are still some open questions, let us know!
yarnyarn build:libsyarn workspace @trezor/connect-webextension buildyarn workspace @trezor/connect-iframe build:core-moduleyarn workspace @trezor/connect-popup devNow you should be able to import from this package, or use directly build/trezor-connect-webextension.js. Popup is running on your localhost, just use it in TrezorConnect.init({ connectSrc: ... })
FAQs
High-level javascript interface for Trezor hardware wallet in webextension serviceworker environment.
The npm package @trezor/connect-webextension receives a total of 442 weekly downloads. As such, @trezor/connect-webextension popularity was classified as not popular.
We found that @trezor/connect-webextension demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
November CVE publications fell 25% YoY even as 2025 totals rose, showing how a few major CNAs can swing “global” counts and skew perceived risk.

Security News
React disclosed a CVSS 10.0 RCE in React Server Components and is advising users to upgrade affected packages and frameworks to patched versions now.

Research
/Security News
We spotted a wave of auto-generated “elf-*” npm packages published every two minutes from new accounts, with simple malware variants and early takedowns underway.