None of this required Javascript. At all. The same potential attack could have been done with good ol' forms. Sure, you think you're signing into "BigBensSuperStore.com", but you're actually handing your credentials right over to "BigBensSuperStore.net".
JavaScript (and other forms of executing logic within the browser) have made the situation worse, though.
To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.
If a malicious site gets your password, I'm not sure why it matters whether it happened in the frontend or not.