This is completely unacceptable. You're treating this as though the author was publishing a list of
vulnerabilities about sites. That's not what the author did. The author published a list of sites that are already infected with malware and thus are dangerous for users to visit. This is a public service and there is zero expectation of "responsible disclosure" to the sites. The only thing that disclosing to the sites without telling the public does is protect the reputation of the site, but there's no expectation for anyone to try and protect the reputation of sites that are serving malware.
> We did not feel comfortable hosting information that could be construed as an open invitation for malicious users to exploit.
The sites were already exploited. That's the thing. At best I can see the argument you're making being "we don't want the sites to get exploited a second time", but that really shouldn't be a concern. The sites were already exploited, there's nothing left to protect. And publishing a list saying "this site has malware on it" doesn't actually tell anybody how the site was vulnerable anyway, unlike disclosing security vulnerabilities which by their very nature informs people how to take advantage of them.