If they use CSRF tokens, this wouldn't be possible.
None of this has anything to do with cross-site scripting. It's a MITM attack. CSRF doesn't come into play.
Here, the real form can be accessed from the attacker's browser, not the victim's, hence the attacker knows the CSRF tokens. CSRF doesn't protect against phishing.
I'd assume there's CSRF on the login page, hence why I said: "hope ... Google notices the source IP or user-agent of the attacker"