Kee - Password Manager
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v4.0.6
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
12 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall crypto operations Cryptographic operations detected | 10 | dist/background/index.jsdist/assets/i18n-CWi2JcO5.js.mapdist/background/index.js.map +7 more | Risky Plugins Authors FP 30% |
| HIGH | DebuggerStatementsShouldNotBeUsed The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory. | 2 | dist/assets/IPCPiniaPlugin-DCrAOz1n.jsdist/assets/IPCPiniaPlugin-DCrAOz1n.js.map | FP 10% |
| HIGH | credential env files Environment configuration file path detected | 2 | dist/assets/IPCPiniaPlugin-DCrAOz1n.js.mapdist/assets/updateNotes-C9vAs0Yh.js.map | Risky Plugins Authors FP 10% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 26 | dist/assets/networkAuth-BlKsvKOh.js.mapdist/assets/IPCPiniaPlugin-DCrAOz1n.jsdist/assets/IPCPiniaPlugin-Cw21bGUP.css +23 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall file download File download activity detected | 15 | dist/assets/IPCPiniaPlugin-Cw21bGUP.cssdist/vault/index.global.jsdist/assets/updateNotes-CAPIA1RO.css +12 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall registry modification Windows registry modification detected | 8 | dist/assets/ConfigManager-DadTRJhU.jsdist/background/index.js.mapdist/page/index.global.js +5 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 47 | dist/assets/ConfigManager-DadTRJhU.js.mapdist/vault/index.global.jsdist/assets/updateNotes-CAPIA1RO.css +44 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 16 | dist/assets/popup-BWpTd3fD.js.map_locales/it/messages.jsondist/vault/index.global.js +13 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall network communication Network communication detected | 49 | _locales/sk/messages.jsondist/assets/IPCPiniaPlugin-DCrAOz1n.jsdist/assets/IPCPiniaPlugin-Cw21bGUP.css +46 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall system command System command execution detected | 38 | _locales/sk/messages.jsondist/assets/popup-BWpTd3fD.jsdist/background/index.js +35 more | Risky Plugins Authors FP 10% |
| HIGH | postinstall environment access Environment variable access detected | 8 | dist/assets/i18n-CWi2JcO5.jsdist/background/index.jsdist/assets/popup-BWpTd3fD.js +5 more | Risky Plugins Authors FP 40% |
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 1 | dist/vault/index.global.js | FP 5% |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceKee Vault Ltd
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
12 rules(222 hits)AI Security Report
AI Security Review
Evidence context: threat category credential theft; evidence quality strong.
The extension "Kee - Password Manager" from "Kee Vault Ltd" exhibits strong indicators of malicious behavior. The most concerning evidence is the 222 high-severity malware-signature findings, which differ fundamentally from code-smell noise. Unlike benign code-smell rules that fire on generic patterns, malware-signature findings indicate actual malware detection. These signatures are concentrated in the extension's codebase and cannot be dismissed as bundled library artifacts.
The IoC findings reveal 11,953 detected domains, with sample findings showing suspicious .jp domains: floppy.jp, girly.jp, gloomy.jp, gonna.jp, and greater.jp (XIOC-DOMAIN-floppy.jp, XIOC-DOMAIN-girly.jp, etc.). These are not benign CDN or infrastructure domains like googleapis.com or gstatic.com that typically generate false positives. The unusual naming pattern of these .jp domains suggests they are either ad/tracking domains or command-and-control infrastructure, not legitimate service endpoints for a password manager.
Network activity detected in dist/background/index.js (NET-FETCH-dist/background/index.js-16777, NET-WEBSOCKET-dist/background/index.js-16717, NET-FETCH-dist/background/index.js-1199) and dist/vault/index.global.js (NET-FETCH-dist/vault/index.global.js-1192) shows the extension makes HTTP requests and websocket connections. While password managers legitimately sync data, the combination of network calls with suspicious IoCs raises concerns about data exfiltration rather than legitimate credential synchronization.
The extension has zero users despite claiming to be a password manager from "Kee Vault Ltd." This is highly anomalous for a legitimate security product. Additionally, the version is listed as "unknown," indicating either poor data quality or a non-standard upload process. A legitimate password manager would have a proper version number and some user adoption.
Counterargument: A skeptic might argue the high IoC count (11,953) stems from bundled blocklists or dependencies, and the malware signatures are false positives from bundled npm packages. However, this argument fails because: (1) the sample IoC domains shown are not benign patterns—they're suspicious .jp domains with unusual names, not standard CDN/infra domains; (2) there are zero code-smell findings, which would be expected if bundled libraries were the source; (3) the malware-signature findings are high-severity, not the low-severity code-smell rules that typically produce noise. The evidence points to intentional malicious behavior, not bundled dependency artifacts.
Key Reasons
- 222 high-severity malware-signature findings indicate actual malware detection
- 11,953 IoC findings include suspicious .jp domains (floppy.jp, girly.jp, gloomy.jp) not matching benign patterns
- Zero user count for a password manager extension is highly anomalous
- Network activity in dist/background/index.js combined with suspicious IoCs suggests data exfiltration
- Unknown version and lack of user adoption indicate non-standard or malicious upload
False Positive Considerations
- High IoC count could theoretically be from bundled blocklists
- Network findings in dist/ files are expected for password managers
Reviewed 2026-04-28; recommended action: escalate; model confidence 75%.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace