The reason they implemented it that way is because Google did not yet provide APIs to facilitate contact import. As Google adopted more secure standards like OAuth, LinkedIn started using the official GMail API features like "import contacts," rather than logging into your account on your behalf.
People underestimate just how far privacy/security have come since 2013 (pre-Snowden), when even major websites still used HTTP on their payment portals. Someone could sit in a coffeeshop with FireSheep and alter your Amazon order. Privacy enhancing features like OAuth, TLS, and 2FA have only become widespread in the last 7-8 years.
Giving them your password so they can login on your behalf is just as egregious, IMO. Then again, Plaid did the same thing with your bank account and created a multi-billion dollar business out of it.
Until OP provides proof I doubt this claim from such a big service like LinkedIn.
That is entirely different than what was claimed. The claim was platforms were running "credential stuffing" attacks against their own users by attempting logins to other platforms by guessing that they use the same email address and password for both.
LinkedIn asks me to sync my contact/address book information from another source. After the import runs they show you connections that match your contacts sometimes in the connections tab.
https://www.linkedin.com/help/linkedin/answer/1278/syncing-c...