Not sure about the how or why but I can imagine a malware BHO is able to capture all requests and modifying them before sending it to the "real" website and the malware's logging site..