Researchers have spotted fake social buttons plugins that attackers are using to compromise websites and redirect visitors to the Angler exploit kit. There isnt even a direct injection of a landing URL for the exploit kit inside the compromised sites source code. Instead of injecting an Angler URL into the site’s source code, they inject a malicious JavaScript call along the lines of http://social-button[.]site/analytics.js. The malicious code activates and takes the visitor from one intermediary stop to the next until arriving at their final destination: a landing page.”]
Source: https://grahamcluley.com/fake-social-button-code-websites-attacks-visitors-angler-exploit-kit/