Earlier quoted context omitted.
That's correct though. Even if the passwords weren't stored at all, malware could just install a keylogger and record them when you typed them in.
The fact that there are ways to obtain passwords even when they are not stored unencrypted is not really a reason to make it as easy as possible for malware to get every password on your system.
This is exactly the thing that Google spent months trying to tell people when it was refusing to include password access to the password list. That extra password does nothing to increase security, and may be counter productive.