Use the desktop or web vault directly, don't use the browser plugin.

How are they clearly less susceptible to a supply chain attack?

Maybe the web vault, but then we do not know when it's compromised (that's the whole idea); so we trust them not to've made a mess...