Source: Steam Forums
We've tracked a recent rash (ok...more like a plague) of account hijackings to the SixSteam Hack that's floating around on the Internet. We are still looking into exactly how this is being accomplished. If you are using SixSteam (BTW...a violation of the Steam Subscriber Agreement...just in case you are wondering) and you still have access to your account change your account password immediately, then delete SixSteam before you login again (or else you run the risk of having your new password stolen as well). If you have had your account disabled you need to create a Support Incident by clicking on the Support link above and for in your subject title it "SixSteam Hijack", we will get to these as time permits. Also. Just a reminder. No one from Valve / Steam will EVER contact you via an Instant Messenger Client and ask you for ANY login information. Period.
SixSteam (some version of it at least) is stealing passwords. Use it at your own risk and remember that it is a violation of both the EULA and the Steam Subscriber Agreement so please don't complain if your account gets hijacked and / or shut off in the future.