The problem is not sites hosting malware. The problem is man-in-the-middle attacks on javascript loaded in the clear on sites otherwise using HTTPS. If an attacker can replace a bit of JavaScript that gets loaded into the page, that somewhat defeats the purpose of using SSL.