malware affecting backend of wordpress website-could be .htaccess file
That directive blocks access to any Python, PHP or exe files. If your site has been compromised, delete the whole thing and restore it from a known good backup. There are thousands of files, and going through them all trying to detect tampering by someone better with the language than you simply isn’t feasible.