Thanks for the concern. It's OK -- they sent me a code a few minutes ago, and it checks out.
I know a phishing operation would want email/pass directly, but I was also worried that they could do something else with the PayPal order #. Not sure what triggered the additional information check; I purchased without first registering an account, it was the first order I've made, could have been the IP address I'm at is within a block of suspect addies... I dunno, whatever. It worked.