I know of atleast one person whose account has been compromised. He swears he didn't give out his creds to any service. My guess is this is a 0-day being exploited
I remember this being discussed at Defcon. Wouldn't surprise me if someone managed to script a JavaScript DDoS worm. It really wouldn't be too hard to do.