Fresh WordPress install from RackNerd panel yesterday. Sent ticket yesterday when I found base64 in footer. Made test order on new account, same image, same payload.
File hash matches between both installs: 4a7f...d2e9. Not in upstream WordPress. Specific to RackNerd "Optimized WP 6.4.3" image.
Found malicious domain in wp-includes/js/crop/angel.php. Very creative path.
Cheers! Following this closely.