Do you have any browser extensions enabled? I've seen similar before where it wasn't the page itself that injected it - rather it was injected by a compromised/sold extension that has permissions on all pages.
Not this time. Go to crookedtimber dot org and you can still see it. Just don't follow the instructions... but clean your browser afterwards! It even supports Macs. But the Mac clipboard content is just "Oops...". P.S.: even worse: the crookedtimber site itself is infected. No third-party attack. It registers a service worker on the user's browser that stays even when you leave the site. Be sure to clean up the stora…
It then spins up the ClickFix attack - limited to one time per day. I haven't dug into the payload given by the ClickFix attack yet.
For people that have visited while it exists:
1. On Chrome go to chrome://serviceworker-internals search for crookedtimber and unregister the ServiceWorker
2. On Firefox go to about:debugging#/runtime/this-firefox, search for crookedtimber and unregister the ServiceWorker.
If you want to be even safer - just clear all local data for CrookedTimber.