I put that warning in my plugin because a lot of malicious code I find adds malicious content to the infected site by hijacking the output buffer. There are legitimate uses for adding a callback function to the output handler, but ZM5j2q0shf_callback sounds malicious to me.

If my plugin is not finding the malicious code I can look for it for you. This may be a new threat that is not yet in my definitions.