Forgive my ignorance, if anyone knows of an initiative that does what I am about to suggest... It's an idea off the top of my head, without too much thought: Is it about time we start to sign our javascript so that browsers will only execute the JS if it can verify the signature? I know, there are so many drawbacks, especially for those of us who are developers, but I'd value security on the Internet over the additional development overheads.
Or depreciate HTTP and enforce HTTPS only?