16
Well, even if i detect the script you will have to reinstall XOOPS and modules, sorry. I have detected changes even for those modules using TRUST PATH.
Maybe know you understand why is not safe to distribute modules. I believe you were hacked by a bot and without really interest of the hacker. But if the hacker manage to manipulate your zipped files then you will be infecting other hosts.
My suggestion is:
If you insist in distribute modules please use a separated server to host the files. Don´t keep demos and modules together.