The frontend container ran `next dev` bound to 0.0.0.0:3000 with the
host source directory bind-mounted rw into it. Over months this let
attackers write files directly onto the host filesystem, which then
got swept into git by an unrelated Gitea ZIP restore. Removes 4 UPX-
packed ELF binaries and a defacement marker (cox.txt/html).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gh2UXUQUVBWroWEnn1FLFG