Isn't the more common problem that the extension contains malware from Google/FB? (This is definitely the case for phone apps.)
How do you deal with side channels when the page is running javascript that's being served by the attacker?
(Little Rat sounds like a great tool; I've been meaning to check it out.)