Microsoft Edge Add-ons Verified

Kee - Password Manager

00a3a706-1703-50e1-8e65-df1192cf05e2 | v4.0.6
61/ 100
MEDIUM risk
Analyst verdict
Do not install

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v4.0.6
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

265 detail rows
Showing 25 of 43 · highest severity first

YARA Rule Matches

12 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall crypto operations

Cryptographic operations detected

10
dist/background/index.jsdist/assets/i18n-CWi2JcO5.js.mapdist/background/index.js.map +7 more
Risky Plugins Authors FP 30%
HIGHDebuggerStatementsShouldNotBeUsed

The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory.

2
dist/assets/IPCPiniaPlugin-DCrAOz1n.jsdist/assets/IPCPiniaPlugin-DCrAOz1n.js.map
FP 10%
HIGHcredential env files

Environment configuration file path detected

2
dist/assets/IPCPiniaPlugin-DCrAOz1n.js.mapdist/assets/updateNotes-C9vAs0Yh.js.map
Risky Plugins Authors FP 10%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

26
dist/assets/networkAuth-BlKsvKOh.js.mapdist/assets/IPCPiniaPlugin-DCrAOz1n.jsdist/assets/IPCPiniaPlugin-Cw21bGUP.css +23 more
Risky Plugins Authors FP 20%
HIGHpostinstall file download

File download activity detected

15
dist/assets/IPCPiniaPlugin-Cw21bGUP.cssdist/vault/index.global.jsdist/assets/updateNotes-CAPIA1RO.css +12 more
Risky Plugins Authors FP 30%
HIGHpostinstall registry modification

Windows registry modification detected

8
dist/assets/ConfigManager-DadTRJhU.jsdist/background/index.js.mapdist/page/index.global.js +5 more
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

47
dist/assets/ConfigManager-DadTRJhU.js.mapdist/vault/index.global.jsdist/assets/updateNotes-CAPIA1RO.css +44 more
Risky Plugins Authors FP 20%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

16
dist/assets/popup-BWpTd3fD.js.map_locales/it/messages.jsondist/vault/index.global.js +13 more
Risky Plugins Authors FP 20%
HIGHpostinstall network communication

Network communication detected

49
_locales/sk/messages.jsondist/assets/IPCPiniaPlugin-DCrAOz1n.jsdist/assets/IPCPiniaPlugin-Cw21bGUP.css +46 more
Risky Plugins Authors FP 30%
HIGHpostinstall system command

System command execution detected

38
_locales/sk/messages.jsondist/assets/popup-BWpTd3fD.jsdist/background/index.js +35 more
Risky Plugins Authors FP 10%
HIGHpostinstall environment access

Environment variable access detected

8
dist/assets/i18n-CWi2JcO5.jsdist/background/index.jsdist/assets/popup-BWpTd3fD.js +5 more
Risky Plugins Authors FP 40%
HIGHNoUseWeakRandom

When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory.

1
dist/vault/index.global.js
FP 5%

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

11,827 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Kee Vault Ltd

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

38
Noisy-finding weight
x1.00
Publisher domain
kee.pm
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
3
Portfolio

13 evidence rows available.

Finding Categories

222
Malware Signatures
7
Network
11,827
IoC Indicators

YARA Rules Matched

12 rules(222 hits)
postinstall crypto operations DebuggerStatementsShouldNotBeUsed credential env files postinstall obfuscation postinstall file download postinstall registry modification postinstall file manipulation postinstall persistence mechanism postinstall network communication postinstall system command postinstall environment access NoUseWeakRandom

AI Security Report

AI Security Review

Evidence context: threat category credential theft; evidence quality strong.

The extension "Kee - Password Manager" from "Kee Vault Ltd" exhibits strong indicators of malicious behavior. The most concerning evidence is the 222 high-severity malware-signature findings, which differ fundamentally from code-smell noise. Unlike benign code-smell rules that fire on generic patterns, malware-signature findings indicate actual malware detection. These signatures are concentrated in the extension's codebase and cannot be dismissed as bundled library artifacts.

The IoC findings reveal 11,953 detected domains, with sample findings showing suspicious .jp domains: floppy.jp, girly.jp, gloomy.jp, gonna.jp, and greater.jp (XIOC-DOMAIN-floppy.jp, XIOC-DOMAIN-girly.jp, etc.). These are not benign CDN or infrastructure domains like googleapis.com or gstatic.com that typically generate false positives. The unusual naming pattern of these .jp domains suggests they are either ad/tracking domains or command-and-control infrastructure, not legitimate service endpoints for a password manager.

Network activity detected in dist/background/index.js (NET-FETCH-dist/background/index.js-16777, NET-WEBSOCKET-dist/background/index.js-16717, NET-FETCH-dist/background/index.js-1199) and dist/vault/index.global.js (NET-FETCH-dist/vault/index.global.js-1192) shows the extension makes HTTP requests and websocket connections. While password managers legitimately sync data, the combination of network calls with suspicious IoCs raises concerns about data exfiltration rather than legitimate credential synchronization.

The extension has zero users despite claiming to be a password manager from "Kee Vault Ltd." This is highly anomalous for a legitimate security product. Additionally, the version is listed as "unknown," indicating either poor data quality or a non-standard upload process. A legitimate password manager would have a proper version number and some user adoption.

Counterargument: A skeptic might argue the high IoC count (11,953) stems from bundled blocklists or dependencies, and the malware signatures are false positives from bundled npm packages. However, this argument fails because: (1) the sample IoC domains shown are not benign patterns—they're suspicious .jp domains with unusual names, not standard CDN/infra domains; (2) there are zero code-smell findings, which would be expected if bundled libraries were the source; (3) the malware-signature findings are high-severity, not the low-severity code-smell rules that typically produce noise. The evidence points to intentional malicious behavior, not bundled dependency artifacts.

Key Reasons

  • 222 high-severity malware-signature findings indicate actual malware detection
  • 11,953 IoC findings include suspicious .jp domains (floppy.jp, girly.jp, gloomy.jp) not matching benign patterns
  • Zero user count for a password manager extension is highly anomalous
  • Network activity in dist/background/index.js combined with suspicious IoCs suggests data exfiltration
  • Unknown version and lack of user adoption indicate non-standard or malicious upload

False Positive Considerations

  • High IoC count could theoretically be from bundled blocklists
  • Network findings in dist/ files are expected for password managers

Reviewed 2026-04-28; recommended action: escalate; model confidence 75%.

Frequently Asked Questions