There was a hole in cPanel. I read a security notice from 21.6.2007 about attacks with MPack. You are sure that your hoster close the holes in cPanel? This was used in 2006 to prepare lots of webserver with iFrames and now this servers respond to the MPack attack and deliver malicious code to the users.