I had this malware yesterday on a fresh domain and webhosting. Just when I finished the template setup after 7 hours of work. ??
Basically I deleted the functions.php from the template I had installed. Then I deleted all other templates not used as well. It let me in the admin, so I installed Wordfence and performed a scan. Now it’s working fine (after 1 day testing). The scan also found there is a depreciated file class.wp.php in the wp-includes folder. It was 0 kb large, so I got rid of that as well but since my host supports WP instalation tools in the webhost, that file got back and this time it wasn’t 0 kB. So I guess it was infected as well…