Thanks for the response Sania!
I actually found that first thread and read it yesterday. I’m not sure if my situation is different, as I’m pretty new to this, but the site doesn’t appear to be hacked. Scans from Wordfence and Sitelock found nothing. Bluehost is running a scan on their side but it hasn’t finished yet. I of course will keep monitoring for any signs of site compromise.
Is there any way that a WordPress update could prompt the default plugins to re-install? Or for the default setting of auto-update to be re-selected?