Investigate Suspicious Magento Checkout Form

Job ID: 40018561

Budget: $10 – $30 USD

I run Magento 2.4.6-p1 on www.kaimbatorium.ru. Overnight the checkout started doing something odd: instead of offering the two gateways that are enabled—“Credit Card (via a third-party service)” and “Bank Transfer”—a single credit-card entry form hijacks the page. Submitting any card data immediately throws an error, then the usual payment options appear.

No new extensions or plugins have been installed, and I can reproduce the issue on every browser and device I test. That rules out user-side glitches and points to a rogue module, theme override, injected JavaScript or some other compromise inside the codebase.

What I need now is a thorough Magento audit that:
• pinpoints the exact file, module or script responsible for injecting the bogus form,
• removes or neutralises it without touching core integrity,
• confirms that the legitimate gateways load and process orders normally afterward, and
• documents the root cause so I can prevent a repeat.

I’ll provide SSH and admin access through a secure channel. Please use standard Magento diagnostics (developer mode, verbose logging, bin/magento commands, etc.) and supply any fixes as version-controlled patches or clear step-by-step instructions. My priority is to restore a clean, reliable checkout as quickly as possible.