i still have no idea how they got that code in the header.php. Anyone have any ideas?
In my case, the attack was from "/blog/wp-content/themes/default/functions.php", which isn't even a theme in recent WordPress builds; it's simply been left over from the many upgrades over the years.
The other most common route for such injection is not always WordPress itself, but instead through insecure, third-party themes, since theme designers are not always programmers.