Ouch, telling people not to update... this wasn't a bug in 7.1. Perhaps consider your usage of @wp_rocket. This is also part of the risk of using plugins outside the official plugin directory, which has many alternatives that seemed fine on the 7.1 release day.
@sucurisecurity vi temporarely files have nothing to do with -swapme files, those start with a dot and end in .swp. In your case, check bash profile for alias ls='ls -I "*swapme"' or similar. I presume is not just magento infected but the whole system.
Excited to share our goals for @polar_sh v1.0 and announce that we've raised a $1.8M pre-seed to help us fix open source funding!
It's time a platform emerged that empowers open source maintainers to become independent entrepreneurs at scale. Let's build
https://t.co/zT6GXL9hl7