It is a new server set-up for first time with WPMU and 5 plug-ins.
It appears on your site that we am not the only ones. At the time the plug-in was installed, code was added to the sidebar which included an iframe. Within minutes the iframe appeared on other pages on the server. We believe it takes advantage of the PDF creation tool and in short the hackers are injecting javascript into the index, or default pages or other pages on the server.