>> We created a rogue SQLite database that exploits the software used to open it.
So, here, they are replacing the whole database and then stealing the passwords? I would guess that if a malicious actor has that kind of access to the system, all is lost.