It's worse now because browser extensions auto-update which means that when a malicious actor buys an extension they gain access not only to future users but to all current users as well. Also, the Chrome Extension Store publicizes how many users each extension has, which allows malicious actors to operate extremely efficiently as they can easily find extensions to acquire and they know exactly what they're buying.