If a malicious site gets your password, I'm not sure why it matters whether it happened in the frontend or not.