The affiliate link hijacking was not opt-in. How could anything remotely like this be accepted in a privacy focused browser?
When Firefox had the mr robot extension incident everybody was (righfuly so) mad, but that was way less damaging than altering users' intent.