Users can be advised to install an ad-blocking plugin for their web browser to protect themselves. Since Google serves adverts from domains other than google.com, users can continue to use the google.com domain for search while at the same time blocking the malware coming from ad networks.
Surely, if the second - linking to wsj isn't known to serve malware.
Further, if you do not have some trust in your browser to go to potentially compromising sites - you need to change browser or stop browsing.
But, you can also use the Web Archive and check every domain yourself within their waterfall chart: http://web.archive.org/web/20150126072317/http://www.malaysi...
Looks like a bunch of static assets delivered by: fonts.googleapis.com, fonts.gstatic.com, pbs.twimg.com, and www.youtube.com. Looks similar to what I saw post-defacement/pre-fix.
IMO it would be much more sensible to serve malware off of a page that _doesn't_ announce it has been hacked.
And if you're lucky the online reporters also have twitter/fb account info on their PCs. I guess this is how the various compromises of twitter accounts have been done.