It targets the local autofill functionality in the browser, so it could conceivably have occurred in any password manager with browser/autofill integration. Including those that use a local password store.
What's happening is that this extension auto filling the password in unintended sites. Where it is getting passwords from (offline or from cloud) is immaterial for this case.
This bug could easily occur in Chrome/Firefox's built-in password manager autofill, though I must admit I have slightly more implicit trust of the developers behind Chrome/Firefox than of Lastpass (instinctively; this may well be unwarranted).
password reuse < own memory/manual storage < synced unencrypted 3rd party storage < synced encrypted 3rd party storage < custom encrypted storage < some custom crazy HSM which doesn't allow you to get more than X passwords per minute and notifies you on each get()
There's another dimension for cross-platform support somewhere in there. At the moment if you want your passwords saved and shared between desktops and mobiles, the best solution I'm aware of is 1password with separate sync (dropbox/icloud) - and you're still trusting the 1password app. You can go further, but you're starting to destroy usability on the way. Lastpass / 1password is still a valid choice that's better than many alternatives.
It stores your data locally, is suprisingly easy to use and relies on battle tested GPG.
From the website: "The community has even produced a cross-platform GUI client, an Android app, an iOS app, a Firefox plugin, a Windows client, a pretty Python QML app, a nice Go GUI app, an interactive console UI, Alfred integration (1) (2) (3), a dmenu script, OS X integration, git credential integration, and even an emacs package."
The lack of integration then with the rest of the OS is actually a security benefit.
It works pretty well. Different password for each site, I only have to remember a few things, and it would take several compromises (and a weirdly dedicated attacker) to work out my algorithm.
For example, my 'insecure' fixed part might be 'Tenk5$' (I recommend including uppercase, lowercase, a number and a symbol in that part to get around idiotic password requirements). Then my algorithm could be 'the last 5 letters backwards, skip the first vowel'. In which case my password for HN would be 'Tenk5$rtani'.
Some need Lower-/Uppercase, some with numbers, some with special Chars, some restrict to minimum of x chars, some use a maximum.
Your system works not for all things, i use a similar system, but store a bunch of passwords with last pass. Only really important passwords are in my head.
I keep meaning to collate idiotic password rules so you can see for sure which patterns work in all of them, but I've never got around to it.
That has not worked well for me. I have lost a small amount of bitcoin, and some encrypted homedirs and encrypted hard drives.
Use that algorithm widely enough and several compromises are guaranteed. The only thing protecting your password is that url manipulation.