tomspark wrote:
honestly this is the kind of stuff that makes you realize how many layers of trust we just stack on top of each other and hope works out. hiding malicious code in a 1x1 pixel svg is genuinely clever though — most security tools aren't even looking there because it seems irrelevant. the magento targeting makes sense too since a lot of smaller stores run it and probably aren't keeping up with patches. this is why I'm paranoid about where I punch in payment info online, even on "legitimate" sites.