One of our readers discovered that that some of websites having PayPal portal for payment are vulnerable and can be exploited using simple javascript. The javascript bypass the payment page and redirect to download page.
He have already informed the PayPal about this issue.
There's also been quite a few things similar lately, for example I just saw another code snippet which was custom made to get a certain type of items free (via paypal's flawed checkout) at a certain site posted on one of those public notepad type sites. And so did thousands of hackers and scammers.