So done a much deeper analysis - there is an loader injected at the Wordpress side which triggers a read of a payload from a smart contract on the Ethereum chain. It stores this in localStorage, registers a ServiceWorker etc so it is persistent.
It then spins up the ClickFix attack - limited to one time per day. I haven't dug into the payload given by the ClickFix attack yet.
For people that have visited while it exists:
1. On Chrome go to chrome://serviceworker-internals search for crookedtimber and unregister the ServiceWorker
2. On Firefox go to about:debugging#/runtime/this-firefox, search for crookedtimber and unregister the ServiceWorker.
If you want to be even safer - just clear all local data for CrookedTimber.