This community is just as bad as r/linuxmemes on Reddit. Half of it is just Windows memes, 30% is people going "Linux good", 20% is this, and only about 10% are actual Linux memes
The client doesn't store passwords at all, but the client does store your token in localStorage (it's necessary so that we can make authenticated requests). The only way your account could get hacked is if they gain access to your browser and look through localStorage. If they have access to your computer, you have other problems though. If they do gain access, you can invalidate the JWT by changing your password.
I like this meme format