The site I’ve seen infected with this was compromised via revslider, or at least that’s how it looks. It was running a very old version, I don’t know at this point if that’s how everyone is infected or if it varies. Revslider can be at /plugins/revslider/ but can also be buried inside of your theme if it includes the slider itself.
I believe the attacker is able to upload a file into /revslider/temp/update_extract/, and then open that file up to compromise the site.
For those of you that are seeing this problem, do you have revslider somewhere on the site? I would take a look at the /revslider/temp/update_extract folder (and the folders inside it) to see if anything looks suspicious. The file we found had an innocuous name, but opening it up was it obfuscated and clearly a malicious file. You can also open up your access logs and see if someone is accessing files that include ‘update_extract’ in the URL.