BGP hijack turns software update channel into malware delivery vector

Attackers hijacked IP address blocks belonging to Softaculous by exploiting routing misconfigurations at Hetzner Online and weak TLS certificate validation. They then used those addresses to distribute malicious updates disguised as legitimate software, targeting Virtualizor management platforms. The incident was compounded by Softaculous's failure to cryptographically sign update packages, leaving affected servers without a reliable way to detect tampering.
The attack unfolded in two distinct hijack phases over a 33-hour window, with Hetzner Online reclaiming the address space after the first 12-hour incident, only for the attacker to repeat the hijack once Hetzner stopped announcing the correct path. The second phase persisted for nearly 10 hours before a response. Monitoring failures at Softaculous, Hetzner, and transit peer Zet.net allowed the compromise to continue for roughly 22 cumulative hours before detection. BGP expert Ben Cartwright-Cox characterized the lapses as "silly, preventable mistakes," noting that Nexon Host's infrastructure may have inadvertently facilitated the malicious route announcement. The incident underscores how BGP's trust-based architecture remains vulnerable when operators neglect basic route filtering and validation practices.
This incident could erode confidence in software update channels across the hosting and data-center industry, where administrators rely on automated update mechanisms as a trusted backbone. If similar routing weaknesses remain unaddressed, other attackers may replicate this technique, potentially affecting cloud providers, managed service firms, and downstream customers who depend on timely patches. The lack of code-signing verification means affected organizations may struggle to determine whether their systems were compromised, creating prolonged uncertainty. Broader adoption of RPKI and mandatory update signing could mitigate such risks, though industry-wide implementation remains inconsistent.