BGP hijacking attack delivers malicious Virtualizor update

Attackers hijacked BGP routing for Softaculous's update infrastructure, redirecting Virtualizor update requests to malicious servers between August 28 and 30. A malicious update package was delivered to a handful of installations, prompting the vendor to advise checking for a specific systemd service. Softaculous has released a new Virtualizor version with a security analyzer tool and recommends rotating API credentials.
BGP hijacking exploits the trust inherent in internet routing, allowing attackers to intercept traffic meant for legitimate destinations. In this incident, the attacker targeted Hetzner-hosted IP blocks belonging to Softaculous, redirecting update checks and billing portal access to their own infrastructure. Because the diversion lasted roughly 33 hours, any Virtualizor installation that polled for updates during that window was potentially exposed.
Softaculous's response includes a new Virtualizor release featuring a built-in Security Analyzer, alongside plans to adopt cryptographic package signing. The vendor also recommends that affected operators audit their systems for unauthorized SSH keys, scheduled tasks, and outbound connections, and that anyone who entered payment details during the incident monitor their financial statements closely.
This incident could affect hosting providers and their customers, as a compromised VPS management panel may grant attackers control over virtual servers and sensitive client data. The attack may also erode trust in software update mechanisms, which users rely on as a secure channel. If BGP hijacking becomes more common, organizations could face increased pressure to adopt stronger verification methods, though the broader impact likely depends on how quickly the industry responds.