33-hour BGP hijack of Softaculous traffic prompts security scramble
Hosting software vendor tells customers to reset credentials and hunt for malicious packages
A 33-hour BGP hijacking incident affected Softaculous and Virtualizor customers, diverting traffic and potentially delivering malware. The attack began around 20:57 UTC on August 28 when an unrelated network announced a block of Hetzner IP addresses, which Softaculous uses. German hosting provider Hetzner is one of Softaculous's upstream infrastructure providers.
The hijacker secured a valid TLS certificate from Let's Encrypt via the hijack, allowing affected connections to reach their servers without triggering warnings. Softaculous reported the issue to Hetzner on August 29, and Hetzner began announcing the more specific address range, cutting the diversion to almost zero. The hijack returned at around 20:00 UTC, lasting roughly ten hours before being withdrawn on August 30.
During the incident, a given server had a 72% chance of routing through the attacker's server. Softaculous advises affected users to reset credentials and inspect their servers, especially after logging into the Softaculous client area or entering card details during the incident window. It is also urging Virtualizor operators to rotate and restrict their API credentials, check for unknown SSH keys, and regenerate client-area API keys.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.