@brandon unless the site in question had had something like an XSS vuln exploited, this would be very unlikely. Yes, it could happen, but would be unlikely to be used maliciously.
Plus, this can be easily circumvented by not auto filling data and just copying the creds from your mgr instead. Like I said, possible, but not likely. Interesting concept though.