Just a follow up – reinstalling wordpress and running wordfence worked for all the malware. I’ve tightened up security settings on wordfence, changed my username to random upper and lowercase letters,
I haven’t had any issues these last few months, till this week when there was a lapse in the wordpress update for a few days and wordfence flagged posts with a js link inserted. I’ve set updates to automatic, and scheduled a weekly backup of the files and database using BackWPup plugin.
Looks a mild spam link injection attack, fingers crossed.