I don't see how CSRF tokens apply here. They can login as you on another machine.
None of this has anything to do with cross-site scripting. It's a MITM attack. CSRF doesn't come into play.
Here, the real form can be accessed from the attacker's browser, not the victim's, hence the attacker knows the CSRF tokens. CSRF doesn't protect against phishing.