What's to stop any theme author from inserting an on-page credit card number scraper into an obfuscated javascript file or a modified version of jQuery? Just look for common WooCommerce field names on every page load, and if you find something, wait for the visitor to enter their card information and then phone home by loading an image or something else innocuous. I'm not aware of anything that any of the theme distribution channels would be doing to detect or prevent this kind of thing.
Given how easy it would be to construct this kind of attack, given how hurriedly theme-based WordPress sites are built, and given the budget limitations of people setting up theme-based WordPress sites, I tend to think that the main reason we don't hear more about these kinds of attacks is that no one is seriously looking for them.