Magento skimmer injection followed by DB card-data purge

Detects a suspected automated exploitation sequence where a web storefront file (e.g., .phtml, .js, .php) is modified to inject malicious script code (skimmer), followed by an unauthorized SQL DELETE operation on sensitive database tables containing payment, customer, or order information, originating from the same host within a 6-hour window.