Not this time. Go to crookedtimber dot org and you can still see it. Just don't follow the instructions... but clean your browser afterwards!
It even supports Macs. But the Mac clipboard content is just "Oops...".
P.S.: even worse: the crookedtimber site itself is infected. No third-party attack. It registers a service worker on the user's browser that stays even when you leave the site. Be sure to clean up the storage data after visiting that site.
I'm not getting it at all! I'm guessing something about my environment has caused it to cloak itself.
So done a much deeper analysis - there is an loader injected at the Wordpress side which triggers a read of a payload from a smart contract on the Ethereum chain. It stores this in localStorage, registers a ServiceWorker etc so it is persistent.
It then spins up the ClickFix attack - limited to one time per day. I haven't dug into the payload given by the ClickFix attack yet.
For people that have visited while it exists:
1. On Chrome go to chrome://serviceworker-internals search for crookedtimber and unregister the ServiceWorker
2. On Firefox go to about:debugging#/runtime/this-firefox, search for crookedtimber and unregister the ServiceWorker.
If you want to be even safer - just clear all local data for CrookedTimber.