A production site was compromised by malware exfiltrating data to external servers. I detected and removed it within hours, verified the system was clean, rotated all credentials, blocked the attackers at the firewall, and migrated the full Directus + Next.js site to a secure new server.