Is Kaspersky Password Manager safe?

Clean risk

Kaspersky Password Manager reads form fields on every page and routes credentials and passkey operations through a local native host.

The extension injects content scripts into all HTTP and HTTPS pages, serializing DOM structure and input field values (including passwords) on each page load and form interaction, then sending this data to the locally installed Kaspersky Password Manager application via native messaging. It also runs a MAIN-world script on all HTTPS pages that intercepts navigator.credentials.create and navigator.credentials.get, proxying WebAuthn and passkey ceremonies through the native host. All data remains local — no external servers are contacted by the extension itself.

Kaspersky Labv26.0.87.1Chrome Web Store
0Risk
Who publishes it

Kaspersky Lab Switzerland GmbH - no other listings under this identity, 4 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Kaspersky Lab
Declared legal entity
Kaspersky Lab Switzerland GmbH
Registered address
Bahnhofstrasse 69, CHE-114.644.463, Zürich 8001, CH
Registered contact
Limited Liability Company

Shared hosts - 4 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

click.kaspersky.com
Also called by 1 other listing: Kaspersky Password Manager
fl.yantarenergosbyt.ru
Also called by 1 other listing: Kaspersky Password Manager
promessedefleurs.com
Also called by 1 other listing: Kaspersky Password Manager
support.kaspersky.com
Also called by 2 other listings, including Hola VPN

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

What it can do

Permissions this extension asks for, as declared in version 25.2.6.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 26.0.87.1, which we have not unpacked yet.

  • Read and change your data on every site you visit

    http://*/*

  • Read and change your data on every secure site you visit

    https://*/*

  • Talk to a program installed on your computer, outside the browser's sandbox

    nativeMessaging

  • Run its own code inside the pages you visit

    scripting

  • Store data in your browser

    storage

  • See every page you navigate to, as you navigate to it

    webNavigation

  • See the address and title of every tab you have open

    tabs

Where it sends data

Destinations our analysis observed Kaspersky Password Manager contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • com.nm.kpm_v2 (local native host)

    Kaspersky Password Manager sends data to com.nm.kpm_v2 (local native host). Named as a recipient in this extension's own analysis.

Updated 30 September 2026dhnkblpjbkfklfloegejegedcafpliaa