I fell for that attack 2 years ago, when I had a separate Windows installation just for gaming. It was rarely used, so I didn't have a reason to customize it, and I only needed 2 or 3 password there, so I was too lazy to install my password manager (plus I feared it can get compromised in case of malicious mods, RCE bugs in games etc.). I also wasn't surprised that I was logged out, as I didn't remember where I was logged in and where I did not. I'm glad that Steam has working forms to lock an account, and that the attacker wasn't fast enough in changing email address.
I wish the browsers would just open everything in new tabs.