I would suggest:
- Make sure you're running updated Wordpress installations, and that all your plugins are updated.
- If you're running any plugins that are not from the Wordpress repository, disable them. Enable them one at a time and check to see if the malicious code comes back.
- Check that all Wordpress users with admin privileges are ones you know should exist, and change their passwords just in case.
- Change your FTP user/passwords.
Check out these links on making Wordpress more secure:
https://codex.wordpress.org/Hardening_WordPress
Securing WordPress: Hardening Basics | The State of Security
https://www.wordfence.com/learn/how-...rdpress-sites/