2 months ago: https://news.ycombinator.com/item?id=44169115.
Of course Facebook's JS won't add itself to websites, so half of the blame goes to webmasters willingly sending malware to browsers.