Earlier quoted context omitted.
Don't all the ad networks use JavaScript? Has any network never let malicious code from advertisers slip through? (I guess Google? But I'd prefer not to have even more people embedding their js everywhere I browse)
Yes, there are networks that have always remained clean. It's a business problem more than technical. But the topic was smaller sites running 3rd party networks which necessarily only integrate via client-side JS. That has nothing to do with what kind of ads are being run. It's the same exact ad calls to the ad exchanges, just done via HTTP from the server rather than JS in the browser.
Can you name them? The major ones have had persistent failures which make me think this is more due to not being targeted or being some of the niche networks like The Deck which didn’t have capacity to scale up.