Hi folks, I'm having an issue with my site patrickkingart.com where the index.php file reverts back to a hacked version that makes the front end of my site inaccessible (I can still access the dashboard). I try to delete it and it reappears, I upload a working version and it reverts to the hacked version, I run Wordfence scan and it just reverts back with the permissions set to 444.
I've tried reinstalled WordPress and renaming the WP core folders so they were inaccessible in case the malicious script was there somewhere, but it still keeps happening.
WTF is happening and how do I get rid of it??
Edit: this is also happening to .htaccess

Ask your hosting company to run a scan.