@Edent I also had 4 admin accts on all my sites -- randomly generated 8 char user accts with "example.com" email addresses. I also had a new plugin "Head, Footer, and Post Injection" (sounds bad, right?) show up on all my sites. All my stuff is up to date and patched. I did have one of the compromised plugins on one site (podpress) so maybe that was the backdoor but if so, it was a good one.