Malicious script in a public Dropbox folder? That's something new.

According to Google, it infected 387 sites

Was it an infected PC? Or compromised Dropbox account? Or a Dropbox account specifically created for this attack?

More about the hack where that script was used:
