Scam Sniffer traced the exploit to a JavaScript payload embedded via the site’s advertising infrastructure.