@JeremyJ: That's usually caused by the spammer setting setting fake From and Reply-To addresses on the messages they send out, so that bounced mail and/or complaints goes to someone else. Also quite common with mail-based viruses.

If there are signs the account is being abused (i.e. messages actually in the Sent folder) and changing the password doesn't stop it, I'd probably be more inclined to suspect a problem on the client machine than making a broad assumption about Yahoo's infrastructure.