Although..your e-mail address could've been forged. I've seen that happen as well. If that's the case, they didn't steal your password but rather are using a way to make the e-mails seem like they're coming from your account.
However, the thing is: they have the e-mail addresses from your mailing list which might mean they did get on your e-mail account after all.