It appears that the first attack was targeted at
https://github.com/cn-nytimes/ and
https://github.com/greatfire/ [1]. Accessing these two pages still responds with `alert("WARNING: malicious javascript detected on this domain")` which is supposed to be executed on the (innocent) client's browser.
[1] https://news.ycombinator.com/item?id=9275381