Thanks for looking into this! Yes I had open the port 22 and my password was not safe enough I guess. Or alternatively this hack was due a web app I was running in Flask with some vulnerabilities. Stranger thing: the hack happened back in March 2017 but got activated exactly on Jan 1 2018.