Pheace: There's a pretty common variety that circumvents that to be honest. It's a phishing link that leads to a download of a file that looks like it's a picture, but has the extension .scr. If you run it it will run a bot program on your own computer and automatically trade/sell your stuff on the marketplace (or sometimes it's a full blown trojan)
It'd be naieve to think your password needs to get hacked to loose access to your account/items.
Looks like the mentioned exploit was patched pretty quickly, and most of the damage was mitigated because the account automatically gets a temporary tradeban. I know people love to complain about the automatic tradebans but this just proves they're there for a reason :)
ThePunishedSnake: No phishing, just a bug from Valve's end that allow every user to ask a password reset simply by knowing your Steam id. No notification password, nothing. You know the steam id, and if you know how to perform this trick (very easy to do because there are even videos posted in and there, it's very stupid and I'm asking how Valve can leave a giant hole like this), you can change the password.
Even if you've steam mobile authenticator? Just curious, I thought it was as failproof as possible.