ya if it is actually a hack, they could have figured out the path to your htpass file and then injected a script to edit it. or they could be hacking the biller script if it is discoverable.
i doubt it was a hack tho. most likely just a screwed up script somewhere.
you should be using separate pass files for each biller too. all with unique unguessable names.
__________________
#
|