All I know is they are not doing it through the AdminCP. That means they're somehow doing a SQL Injection attack which changes the value in the database. This is the second time the settings ONLY for the PayPal Donate mod have been exploited. No other changes are being made to the forum.
The fraudulent e-mail address that is being added into my settings is:
memogl39@googlemail.com - They have stolen over $100 in donations from my site.
The real pain, too, is that PayPal turns a complete cold shoulder to the issue. I've tried submitting multiple fraud cases with them over this and it never gets any response. Trying to submit through the Resolution Center yields an error message so I tried through the Contact Us forms they have and those don't get a confirmation e-mail or any type of response.
When I alerted the users that their donations went to a fraudulent user, they submitted cases to PayPal and they told them there was nothing they could do... Absolutely ridiculous.