Yea I was having a hard time making the SMS connection. TFA speculates that SMS "could" be used to transmit the hijacked passwords:

It is then possible to intercept a user's password and send it to the attacker via SMS or any other means

pretty far stretch if you ask me...

