they've been doing this phishing since the dawn of time but it still works for some. it should be common sense to see something is wrong if there is the need to login again when you know you are already loggedin. the url of the website is very important to notice here.
My pull request got accepted, MetaMask now blocks the site:

when you aren't sure which app to use your metamask, don't use it. browser apps aren't something you can controll, you may have the privkeys but pick which app to use your metamask.