My site has a problem when new customer checks out a product.
It doesn't happen with the registered account so I can't know until a customer reports this.
Luckily in my country filling in credit card information is not common.
the hacker use href="https://cdn.jsdelivr.net/npm/[email protected]/dist/css/bootstrap.min.css" to collect Customer payment information.
I tried to search that code in public_html but not have any clue.