You need to fix whatever vulnerability has been allowing this exploit. If it’s a crossover attack from another infected site on the same shared hosting server then you should probably move you site to more secure host.

Change all your passwords. Look for any rogue admin accounts in your users. Check the access_log files on your server to see what activity there was at the exact time of the last infection.