If they are putting it into those files then it sounds like they are sticking it into files that are web writable. So, it's possible it's some sort of web based exploit.

What you need to do is look at the timestamps that the files are being modified and then look through the access logs for the same timestamps and see if there is anything peculiar in the logs.

Worked on one similar last week where they had hacked an ad program and were using that to do this same sort of stuff.