Hmm, even though LastPass doesn’t have access to your pass, couldn’t a malicious software update cause attacker to view your passwords when it runs since the software ultimately has access?
This doesn’t seem to be the case in this incident though.
This doesn’t seem to be the case in this incident though.
That's basically what happened in the solarwinds compromise.
So unlikely.