Magecart hides payload in favicon EXIF via third-party scripts, bypassing static analysis and stealing checkout data at runtime.
More fun than it should be, honestly.
How can an extension change hands with no oversight?