Is that different? "Eventually get all of your passwords" sounds just as bad to me, especially since only some passwords are worth anything and my email password can be used to reset all other passwords.
The malware just waits until you use one of these passwords? The threat model of "I have these crazy essential passwords that I literally never use" is worthless. It costs the malware author nothing to wait.