Another idea.
Use .htaccess to protect the archive and put the username and password in a
onclick=javasript:alert link to the archive. Should stop automatic eamil
harvesting without munging the archive email addresses (and redoing the
archive).
Example:
http://www.psmfc.org/~wade/dodge/#reference
One problem with that is that some people have disabled JavaScript. Have
you considered to simply disclose username and password? I assume that
the spam bots aren't smart enough to make use the info anyway.