Don't immediately point the finger at Babiato because there are many possible ways it could have been hacked. Numerous elements, including hosting, plugins, themes, and so on, may be in question here.
Class-avada-admin.php for Avada recently contained a vulnerability (cross-site request forgery).
What Malicious code are they referring to, please?
Do you, as a reseller, have any offshore backups set up?
Does your client have the ability to upload plugins?
Do you have access to the logs?
Please advised