Hackers used a BGP hijacking attack to redirect Virtualizor update requests to a malicious server, allowing them to distribute a fraudulent update to a limited number of installations.
Virtualizor is Softaculous’ legacy web-based control panel, which hosting providers use to create, sell, and manage virtual private servers (VPS).
In an emergency security notice, Softaculous said the attack occurred between 20:57 UTC on August 28 and 06:10 UTC on August 30. During this period, the attacker rerouted a block of IP addresses hosted by Hetzner using Border Gateway Protocol (BGP) hijacking.
The routing attack redirected traffic intended for Softaculous’ software update infrastructure, as well as its client and billing portal, to systems controlled by the attacker.
BGP hijacking happens when a network operator announces a route for IP addresses belonging to another organization. If other networks accept the unauthorized route as the preferred path, traffic can be intercepted, modified, or redirected to a malicious destination.
According to Softaculous, the attack enabled hackers to deliver a malicious Virtualizor update to a small number of systems that checked for updates while the traffic diversion was active.
“We observed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while traffic was being diverted,” the vendor said.
“This affected a small number of servers, not the general Virtualizor user base.”
Because update requests were redirected to the attacker’s infrastructure, Softaculous does not have server-side logs for the affected connections. The company is urging Virtualizor administrators to inspect their systems for signs of compromise.
/etc/systemd/system/java-jre-update.service
Administrators who find this service should rotate and restrict API credentials. They should also audit systems for unauthorized SSH keys, user accounts, scheduled tasks, services, and suspicious outbound network connections.
Users who accessed the Softaculous Client Area or entered payment details during the attack window should change their passwords, review account activity, and monitor payment card statements for unauthorized transactions.
Softaculous said its investigation remains ongoing. At this time, the company has found no evidence that any of its other products were affected by the BGP hijacking incident.
Routing has since been restored, and the fraudulent certificate used during the attack has been reported for revocation. Softaculous has also released a new Virtualizor version, version 3.2.9.9, which includes a “Security Analyzer” tool in the administration panel.
The company also plans to add cryptographic signatures to all software packages and move its update services to more secure infrastructure to help prevent similar supply chain attacks in the future.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



