It’s unlikely to be due to a browser extension. A browser extension that can steal your master password can steal all the other passwords as well, it doesn’t need LastPass for that. More importantly, an extension can only steal your master password when it is used – yet several people reported not having used LastPass for a year or more. It’s still not impossible that an extension has been stealing master passwords for years only for them to be used now, it’s merely unlikely.
Judging by the reports here, the source of the leak appears to be LastPass after all. Given that most people write about old accounts, my original suspicion was https://palant.info/2018/07/09/is-your-lastpass-data-really-... – from all I know, LastPass never investigated whether that websiteBackgroundScript.php issue was already being abused. It was obvious enough that someone might have discovered it independently of me.
If on the other hand you changed your master password recently (and someone had a login attempt on a brand new account) then this theory is moot. While I am aware of a number of LastPass design flaws (see https://security.stackexchange.com/questions/45170/how-safe-...), none of them could be the culprit here. It must be something new then. The weird thing: LastPass must have stored unencrypted passwords somewhere, because reversing 100,000 rounds of PBKDF2 wouldn’t have allowed such large-scale attacks.