HN might be interested in the nature of the hack. It was a MITM attack by listening to background message handlers and impersonating the server.
The extension is not high value enough to build in high security certificate pinning (like some of the twitter replies recommended). I wonder if there is an easier way to avoid this.
Simplehuman for Gmail is what I use. It's a light weight browser extension that makes Gmail work like Superhuman with the same keyboard shortcuts and natural language snooze. https://simplehuman.email
You still get your local contribution; merges are counted as contributions by the person who presses merge. It makes sense in terms of what really happens in terms of Git, I guess.