Kristi Hines said
9 months, 3 weeks ago: @adigaskell That one has been around for awhile. One of the most popular posts on it is this one by the creator of the Thesis WordPress theme: http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php
For those site it keeps recurring on, it’s because the site owner hasn’t found the “backdoor” file that the hack leaves on your website to regenerate the malicious code. I had a different hack hit my website and wrote about cleaning it in this post back in 2010: http://kikolani.com/latest-wordpress-hack-symptoms-solutions-resources.html
The other thing that’s really terrible about it is if you have multiple websites on one hosting account, the hack can spread through all of the files on those websites. I had to clean through 10 at one point – it hit every PHP and Javascript file throughout all of the WordPress installs. Plus it stuck the backdoor PHP file in a random images folder that you normally wouldn’t think to check for issues. It’s a real mess to deal with indeed, but if you take the time cleaning it up the first time, then you shouldn’t have to go through it again.
Oh, also check your own computer out – sometimes the hacks originate from virus files on your own computer that find your FTP information if it’s saved in an FTP program.