Ah, so certainly malicious JS code could misbehave and gain access to your account. But this is true also for someone publishing a desktop client — in practice, people aren't going to check the code going into each release, any more than they're going to inspect the JS running on their page before entering the password.
I think the question of where your password by design will go is very important. If it's transiting the server, suddenly there's a lot more surface area to worry about. Logfiles, databases, and the like suddenly can be called into scope, and an attacker might be able to steal credentials even without being able to substitute out code.
In any case, the great thing about an open ecosystem is that, if you don't like the choices someone else has made, you are more than welcome to make your own implementation with choices you prefer!