This PR fixes a Silent Payments pubkey extraction issue for P2PKH inputs: a third party can malleate the scriptSig such that it contains an OP_CHECKSIG that fails in real validation but succeeds with the dummy signature checker currently used (which accepts any non-empty signature). E.g. for a P2PKH spend with scriptSig
<sig> <pubkey> <bogus_sig> OP_OVER OP_CHECKSIG OP_IF <wrong_pubkey> OP_ENDIF
the EvalScript call would currently result in wrong_pubkey as the top stack item instead of pubkey and thus lead to an incorrect extraction (see the test added in the first commit). Fix this by parsing the scriptSig manually via a .GetOp(...) iteration, looking at all 33-byte data pushes to find the one where the Hash160 (SHA-256 + RIPEMD-160) matches the one in the output script.
Note that an alternative fix would be to keep using EvalScript but use an actual signature checker instead of the dummy one, but for that we need more transaction data in order to enable sighash calculation. Also involving a full script interpreter run including signature checks merely for extracting a public key seems overblown.
This issue was reported by Project Loupe earlier this week (thanks!). From what I saw, none of the existing Silent Payments implementations are affected. I'm planning to add the test case to the BIP-352 test vectors in the BIPs repository as well, next to the existing ones that cover P2PKH malleation.