Even for merchants that use third-party hosted payment forms, it's still common to need to complete SAQ A (a short self-assessment questionnaire) and have quarterly network scans. For example, with PayPal[1]: "Our hosted solution takes a lot of the work out of meeting these standards. The only remaining requirements are a Security Self-Assessment Questionnaire (SAQ) and Quarterly Security Scans."
According to MasterCard[2]: "All merchants that store, process, or transmit cardholder data must be PCI compliant." It's subjective whether using Stripe.js could be considered transmitting cardholder data.
Visa[3] holds Acquirers responsible for ensuring their merchants are PCI compliant. Requirements vary depending on processing volume: "In addition to adhering to the PCI DSS, compliance validation is required for Level 1, Level 2, and Level 3 merchants, and may be required for Level 4 merchants." Notice that for Level 4 merchants, validation only may be required, although those merchants should still be adhering to the PCI DSS.
Stripe has several PCI requirements in their terms of service[4], and their FAQ does seem to indicate[5] that merchants have some responsibility for PCI compliance. According to the TOS "It is your responsibility to comply with these standards." and according to the FAQ: "Most Qualified Security Assesors (QSAs) will want to talk through many of the implementation details before giving an opinion"
Disclosure: I work for Braintree.
Disclaimer: This response is my opinion; I'm not speaking for Braintree.
[1] https://merchant.paypal.com/us/cgi-bin/?cmd=_render-content&...
[2] http://www.mastercard.com/us/company/en/whatwedo/determine_m...
[3] http://usa.visa.com/merchants/risk_management/cisp_merchants...
[4] https://stripe.com/terms/US
[5] https://answers.stripe.com/questions/what-exactly-do-i-need-...
Part of what PCI attempts to address is limiting legitimate access to servers, as well as preventative measures against compromise.
I personally think that Stripe may be within the letter of the law, but not necessarily the spirit.
More people should write about obvious security holes so clearly and logically correct like you do