Was the Pi running public facing services? How did this occur?
It's stealth and has mitigations for DOS attacks.
I already run PiHole, but I might run this on a different box just to keep things simple.
Also, last I checked - port 51820 is reasonably well known, is it safe to use this default when forwarding traffic?
But I agree that there's something other that's not ok. Compromised client (probably a computer) or a compromised router is my guesses.