@LaurentGoderre The proper username/pass fields aren't being subverted at all. This wouldn't be happening on the login page.
On a different page on the same site, the 3rd party ad script creates fields that fool password managers into auto-filling.
@sawaba What I mean though is that a password manager should only fill a field of type password, no matter what the name or ID of the field is. Then the browser prevents the leak of the password in the field.
@LaurentGoderre They create their own password field on a non-login page - it doesn't use the proper one. Some password managers don't differentiate, some actively defend against these types of attacks (e.g. non-visible login forms).
TL;DR - Advertisers are creating invisible login forms to capture any data your password manager is willing to auto-fill.
They're allegedly after your usernames, but there's nothing stopping them from capturing your password as well.
1. Block ads
2. Don't allow auto-fill https://t.co/sn34Adcb7N