Google account's password exposed after authorizing web apps to the account

Hello,

Yesterday I registered accounts on some online storage websites. On that same day’s afternoon, Google notified me about someone had has logged in using my Google account in US (clearly that’s not where I live). So I had to change password and perform a whole PC scan.

http://i.imgur.com/Yz9tQXt.jpg

What I did yesterday were:

Also I logged into this site but I registered long time ago:

Only google account is exposed so far (at least as I know). The computer is clean. I highly doubt that the sensortower and appannie were the cause. I used the same password for all account unless the site didn’t allow it (stupid yes but this account is not my main account).

This is strange because if the hacker just tried the password from website to access to my Google account and accidentally succeeded then he had access to the account database of the site or he was the owner of the site himself.

If the hacker access my account using the Basic account info permission (View your email address - View your basic profile info). Then how was that possible? He only had my email address?!

No suspicious activity so far since I changed the password (I used the phone to change the password).

Can anyone try to replicate the attack with these sites. That would help many people from losing their accounts.

Be advised that I would no longer recommend Chrome as a browser as it is the most insecure one on the block https://forum.avast.com/index.php?topic=178035.0

-http://ge.tt/ is blacklisted
https://www.virustotal.com/en/url/01489a1833d93b7fe89a16258b2c87fd9f78de5923b45a6371f510295dcc1653/analysis/1445522360/

did he just guess your password?
The Top 500 Worst Passwords of All Time http://www.whatsmypass.com/the-top-500-worst-passwords-of-all-time

Top 10,000 passwords are used by 98.8% of all users https://uwnthesis.wordpress.com/2012/08/30/top-10000-passwords-are-used-by-98-8-of-all-users/

Password Generator:
http://passwordsgenerator.net
https://identitysafe.norton.com/password-generator
https://www.grc.com/passwords.htm (this one i use for router passwords)

I used Firefox. And of course I don’t use Chrome much for important stuff since I need to enable some developer mode plugin.

Ge.tt is blacklisted but only reported by 2 sites :
And my password is only using number and normal character but it’s not common password. The brute force method might break it but unlikely by guessing.

Nothing strange happened since I changed the password so I can stop scanning for malware on my PC now. But I’ll absolutely note those sites above to reproduce/find the malicious one.