Interestingly in a world of front-end JS frameworks you could fix this by encoding client-side before submission.
Encrypting user credentials in JS is probably even worse than parsing HTML with regular expressions: http://stackoverflow.com/questions/1732348/regex-match-open-...
Just send it in cleartext, but over properly verified https.
That being said, look at something like blockchain.info.
It adds javascript security on top of https, and for (what seems like) excellent reasons.
To avoid the "hash is a plaintext password" problem you save double-hashed passwords to your database, once in the browser and once on the back-end, twice on the back-end if JavaScript was disabled in your user-agent.
Of course that doesn't solve the problem above, but it still ought to be common practice.