Your site is compromised, and the attacker is likely exploiting a backdoor to exploit your site after it's corrected.
In order to address the problem you need to examine all of the files/folders on the server checking for backdoors. If you haven't already you need to make sure the site is using 1.0.14.
Additionally, as MrHaw noted you need to change all passwords (Control Panel, FTP/SFTP, SSH, Database, and MODX). If you're unfamiliar with checking your site for exploits consider hiring someone to do the cleanup. If it's not done right they will continue to exploit your site, which can lead to other potential problems.
I've cleaned up more sites than I care to admit, and in 99% of the cases simply upgrading MODX in advance would have avoided the problem entirely. On the bright side I've got the process down to an hour