Malware hosting sites rarely stay up for too long. After the first few instances are seen by security vendors, they are added to denylists which, in turn, are fed into other denylists throughout the industry. Malware writers are now turning to commercial file hosting sites to peddle their warez. If these legitimate file hosts are not scanning the content they are hosting, it may force network administrators to block the service altogether. The kicker is that this time we see that GoogleCode seems to have swallowed the bad pill.
The first file in question is hosted at: hxxps://code.google.com/p/onflashplayers/source/browse/AdobeFlashPlayer.exe
You may also recognize it by a few other names as seen here(21/45): https://www.virustotal.com/en/file/12ba2c059963799fda3b48bce3d51f06940c7cdcb7b20559c752acdee2d43594/analysis/1375130106/
We also have reports of this file being downloaded via Dropbox, but it appears to have been taken down at the time of research
This incident sets a precedent that no file hosting service is beyond reproach. Blind trust of specific domains should not be tolerated from an organizational or personal perspective. So set those security privileges to kill and keep one eye open for shady files coming from even a seemingly trusted location.