Looks like it wasn't a false positive after all. http://thehackernews.com/2013/10/google-detected-malware-on-phpnet.html
It turned out it wasn't a false positive as they first thought: two of their servers were compromised. You can read it all on the php.net homepage.