Claude Code Security and Magecart: Getting the Threat Model Right
Magecart hides payload in favicon EXIF via third-party scripts, bypassing static analysis and stealing checkout data at runtime.
More info
