Ok, so this is very clever.
Some infostealer devs are forcing browsers to enter in Kiosk Mode and forcing users to enter credentials on legitimate sites.
Once entered, they are stored in Chrome's password manager, from where the passwords can be easily extracted