I can’t say for sure, but I think it’s some sort of a tinyMCE exploit. However, the hackers seems to be targetting WordPress sites only. The WP blog that got infected on my server didn’t have TinyMCE anywhere in the front end, so there must be some WordPress weakness that allows the hackers to access tinyMCE and use its exploit…