No - it loaded grooveshark.com with the node module "request" and used cheerio to get the session id from the page source. Then API calls are made with the session id and client info. The APIs don't require a login or any authentication
In other words it simulates browsing the grooveshark website, instead of using their public API. I think it's this that they are upset about, but it makes little sense because if people can see something on their browser then that user should just as well be allowed to see it through a script.