Some people blame new web api: http://security.stackexchange.com/questions/93305/insert-hidden-link-in-skype
Apparently there is no official Microsoft statement about the issue yet, apart from the quick note from a community moderator:
"We can confirm continued reports from some Skype users about their accounts being used to send spam and we continue to investigating the cause.
Should your account be affected please ensure to change all your passwords. E.g. if you have a Skype account and a linked Microsoft account you need to change the password for both.
We'll provide another update tomorrow."