It puts it in index.php.
Hmm…It’s been putting it in *every* index.php on my hosting account. Might not be a wordpress plugin. (Could be, though?)
I’m running a cPanel virus scan with ClamAV and hopefully that’ll detect something. Also deleting unnecessary files in hopes that I’ll come across something.
Update: ClamAV Found Nothing.