This .htaccess rule is a malware accomplice, used to tell your webserver which file extension should be executed as a cgi-script. It is not a malware per-se, but it should be treat as an alert and further investigated.
Affecting
Any Apache based web server hosting vulnerable software or with compromised credentials.
Cleanup
Review your .htaccess rules and remove any rule similar to the dump below and look for files with the cgi-script extension that you do not recognize.
Dump
Options +ExecCGI
AddHandler cgi-script .py