First you need to invent a password manager that can be properly used? The one I have runs on my computer and trusts everything else I've ever installed not to have put in a mechanism to observe memory allocated to my browser.
Is that how most credentials are stolen these days?
Most attacks are social engineering. Everything else, to the best of my knowledge, does not target passwords
The biggest attack is persistent login tokens that are stored on a device, eg. Discord has an issue with malware (disguised as DMs from random people asking "do you want to try out a beta for my game") that steals the login token from appdata, using it to purchase a bunch of gifted nitro and perpetuate the scam via that user's account.
Users opening shady attachments or going to amarzön.se and logging in are probably 99% of cases.