Today is going on a news about Yahoo infections. It seems the same attack of facebook, the user simply viewing Yahoo mail page and suddenly, RogueIframe trojan.
Here the original link.
It's more and more dangerous allowing a third party JavaScript applications even if the sources are apparently trusted.