I personally also block access by web browsers to non-standard ports (aka not :80 or :443) via an app firewall (Little Snitch here). In this case it would have warned me when the compromised script would have called home to that endpoint on the non-standard port.

Gotta tackle such issues at different places all at once for sure. It's like wearing 5 digital condoms at once. Too bad there's still some leakage somewhere for sure. B)