We had the same problem at MacHeist (people got their specific macheist+ prefixes targeted with spam). Turned out it was our email provider iContact who were hacked. We weren't the only ones. They posted a non-committal blog post about "investigating the matter", which then mysteriously disappeared when they upgraded their blogging platform.
The hack made real damage to our reputation (the "software bundle" space has a poor reputation to begin with, and receiving spam confirmed people's expectations), and they wouldn't own up to it. Be careful with which third parties you entrust your users' email addresses with.