This would be one heck of a phishing scam to get everyone's Apple ids. Has anyone verified that the site is legit?
Indeed. A site asking for my apple.com password that isn't apple.com? No thanks.
You'd think oauth would just be part of implementing logins, and apple wouldn't be encouraging people to give their passwords to other sites.