It looks like this is the part that includes an external js file:
<script type="text/javascript" src="">
I think it just happened to be after the <link> to your external.php (RSS feed), so it doesn't really have anything to do with external.php. But there's still the question of how someone was able to insert that - you must still have some vulnerability somewhere.