Ok, so the malware runs a keylogger / clipboard logger, gets the password and runs sudo on it's own. Or replaces your shell by putting exec ~/hackedbash into your bashrc
Password on sudo is only useful if you detect the infection before you run sudo
Password on sudo is only useful if you detect the infection before you run sudo
Yubikeys do not fix this issue.
In practice yubikey sudo keeps you much safer today, as almost nobody uses it and malware won't be prepared for it