::
Putting aside that automated withdrawal is not possible on the ledger for an automatic withdrawal from a bad site. let me give you a quick explanation of addresses.
Your addresses that are linked to your crypto transactions are accessible to anyone that has the private key for each address. Each address has its own private key. You cannot send crypto without it. When you sign metamask transactions the metamask wallet is signing the transaction with the private key for the address you are using.
So if you visit a malicious site from metamask (not Ledger) the address you connect with can be drained.
To steal from the other addresses you need the private key for each.
With Ledger you have to physically connect Ledger and approve the transaction on the device.
Here is the important part. If someone has the seed phrase for your Ledger or any other wallet including metamask, they can recreate, very easily, all of your Private and Public keys giving them access to every address in that wallet.
Metamask (not Ledger) Seed phrases can be stolen if you have a weak password for metamask or through downloading malware. Metamask stores the seed phrase on the computer. One precaution is to always logout of metamask when you have finished using it.