3-4 years ago,
A virus infected my "local" pc. It has add 1 line iframe/javascript code all html files. Antivirus program could not find because that innocent. I was deleting all files from server and upload my local backup(!) to server :)
When page runing that line was loading real code.
You can control all external request in html/iframe and js.