Seems like someone who uses LastPass got XSRF'd: view-source: http://ramarchy.com/
The source has changed since your post. If I use LastPass and visited the site, should I be worried? What did the script do?
Re: Ramarchy – a website anyone can edit
#11The script grabbed document.documentElement.innerHTML and resubmitted it as the new page contents. See my post above regarding CSRF.