Where is the signature from this key used? I don't see any signatures or certificates in the crx archive (just the key), and I'm curious as to the trust path here - or is this an internal-to-Google's-extension-site key?
The signature it generates is used by Chrome to determine whether an upgraded extension really came from the same source. With this leaked, anybody could conceivably put up an upgraded, evil version of Axis and Chrome would happily upgrade it behind the scenes. I say conceivably because you still need to either MitM the Chrome store or get Yahoo!'s credentials to the store.