Its not anything in the XF installation, it doesn't contain this code. You've got a security issue on the site which has let someone inject that code, probably into one of the templates, or your browser itself is infected (that seems to be a common issue with this particular malware threat).
I'd run malware scans on your server such as Clamav, rkhunter and chrootkit, along with a full virus scan on your computer.