Hello,
I have found the same Malware about 3 days ago on my Website.
The Malware is located in wp-content/plugins
3 Files (ccode.php helad.php and admin_ips.txt)
For those of you wondering, I had a look into the suspicious code:
The Malware redirects website users to nasty sites and shows them Ads on your website. BUT it filters out Website “Admins” so you will not even see it if a user does not inform you. It finds Admins by “logged in state”, IP adress and Browser Cookies.
The Ads will only show to organic search users, who e.g. find your website on google.
I am not sure yet, if removing the files will solve the problem and why they got into my plugins folder in the first place. Maybe someone else can help?