Let's work through the scenarios:
- Eavesdropping on you, doesn't happen because you use the password manager's autofill.
- Hacking service X, TOTP doesn't matter. They'll have the TOTP shared secret, but who cares anyway, they have access to your whole account.
- Using the same password across sites -> shouldn't happen either, this is why you are using a password manager.
- Phishing: while they cannot access your TOTP secret, they can just ask you a TOTP code while phishing as well and log onto your account.
So what is this scenario where an attacker knows your password, needs your TOTP, but doesn't have it? The primary scenario I can think of is where they somehow compromised your password manager, but you stored your TOTP secrets on a separate, uncompromised device (like your phone).