PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Password Managers Can Be Vulnerable to Malware Attacks

Four popular password managers for Windows 10 can leak your login credentials to the PC's memory, making it possible for hackers to target and steal the data with malware. Password manager makers, however, argue the threat is limited.

 & Michael Kan Principal Reporter

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS

Password managers are a useful way to keeping your internet accounts safe. But the software that runs them isn't always perfect.

According to new research, four popular password managers for Windows 10 can actually leak your login credentials to the PC's memory. That's bad news in the event your computer has been secretly taken over by malware; a hacker could potentially snatch up the sensitive data when the password manager turns on.

The research, published on Tuesday, comes from Independent Security Evaluators (ISE), a Baltimore-based company that examined the security of four products including 1Password, Dashlane, KeePass, and LastPass. The company was surprised to find that the products didn't always encrypt and then delete password data in the PC's background processes. Even the master password, which can be used to unlock all your stored passwords, can be exposed.

For instance, 1Password7 will decrypt all your individual passwords and store them in the computer's memory once the application loads up. The login credentials—including the master password—will also persist in the PC's memory when the product is still running, but in a locked state. "The user must exit the software entirely in order to clear sensitive information from memory," the research adds.

ISE Research 1Pass 2

Dashlane, on the other hand, will only expose a login credential individually, depending on which password the user is seeking to access. Only when the user seeks to update a password will the Dashlane application expose the entire database in plaintext. LastPass exhibits a similar problem, and can also leak the credentials even after the application returns to a locked state.

ISE published the research to encourage password manager vendors to better protect login credentials as they load over a PC, especially when the product reverts back into a locked state.

"Given the huge user base of people already using password managers, these vulnerabilities will entice hackers to target and steal data from these computers via malware attacks," ISE researcher Adrian Bednarek in a statement.

DashLane ISE

But not everyone agrees about the severity of the threat. To pull off these attacks, the hacker has to trick you into installing some malware, which can open your PC to all kinds of mayhem—not just password theft.

"The realistic threat from this issue is limited," 1Password's security developer Jeffrey Goldberg told PCMag in an email. "No password manager (or anything else) can promise to run securely on a compromised computer."

1Password and KeePass also told PCMag that the security issues cited by ISE are nothing new, and have been previously mentioned as known trade-offs with their products. For instance, with the Windows operating system, KeePass must unencrypt some of the sensitive data in order to show you a password.

"Fixing this particular problem introduces new, greater security risks," Goldberg said. 1Password would have to switch to a different, older programing language, which might prove to be less reliable in other ways, and leave users insecure, he added.

LastPass, however, said it's introduced new safeguards to stop potential password theft from malware. For instance, the company's Windows application will now shut down and clear the system memory when the user logs out.

The research from ISE is a reminder to be aware of a password managers' limitations; the applications won't protect your login credentials in the event your PC has been infected with malware that has keylogging, screenshot grabbing, or text copying abilities.

To stay safe, ISE recommends you use reputable antivirus products, and shut down a password manager completely once you're done with it. That'll ensure the product isn't actively leaking your password credentials in the background. To avoid malware, refrain from downloading applications from unknown sources or from mysterious email attachments.

About Our Expert

Michael Kan

Michael Kan

Principal Reporter

My Experience

I've been a journalist for over 15 years. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more. I'm currently based in San Francisco, but previously spent over five years in China, covering the country's technology sector.

Since 2020, I've covered the launch and explosive growth of SpaceX's Starlink satellite internet service, writing 600+ stories on availability and feature launches, but also the regulatory battles over the expansion of satellite constellations, fights with rival providers like AST SpaceMobile and Amazon, and the effort to expand into satellite-based mobile service. I've combed through FCC filings for the latest news and driven to remote corners of California to test Starlink's cellular service.

I also cover cyber threats, from ransomware gangs to the emergence of AI-based malware. In 2024 and 2025, the FTC forced Avast to pay consumers $16.5 million for secretly harvesting and selling their personal information to third-party clients, as revealed in my joint investigation with Motherboard.

I also cover the PC graphics card market. Pandemic-era shortages led me to camp out in front of a Best Buy to get an RTX 3000. I'm now following how the AI-driven memory shortage is impacting the entire consumer electronics market. I'm always eager to learn more, so please jump in the comments with feedback and send me tips.

The Best Tech I've Had:

  • My first video game console: a Nintendo Famicom
  • I loved my Sega Saturn despite PlayStation's popularity.
  • The iPod Video I received as a gift in college
  • Xbox 360 FTW
  • The Galaxy Nexus was the first smartphone I was proud to own.
  • The PC desktop I built in 2013, which still works to this day.

Read full bio