Found a malicious script in Linux server

Job ID: 30689614

Budget: $30 – $250 USD

I have been noticing weird behavior in my server. I found some weird scripts last time, deleted them, installed clamAV and did a full scan, found no malware.
I found scripts now recently again that seem to be trying to change my (super user's) password, disabling https and secure checkout in our e-commerce website that runs on CS-Cart. Here is a snippet of the script ibb.co/kcMqnz8 I have given access to developers and other relevant people in the past but always change passwords. I need:

- An audit of what this script is doing and the damage it has done
- Undo damage
- Try to figure out who did it
- Find other vulnerabilities
- Fix them and fortify the server and db as much as possible
- How to avoid this in the future

Please send a brief bullet point list like the one above explaining what needs to be done/ what you will do for this and your fixed price (budget is just placeholder)