33-hour BGP hijack of Softaculous traffic prompts security scramble
Hosting software vendor tells customers to reset credentials and hunt for malicious packages
A 33-hour BGP hijacking incident disrupted traffic for Softaculous and Virtualizor customers, delivering malware to some installations. Softaculous provides software for the web hosting industry, while its Virtualizor control panel helps providers manage virtual private servers. The hijack started around 20:57 UTC on August 28 when an unrelated network announced a block of Hetzner IP addresses, diverting traffic through an attacker-controlled server.
The attacker took advantage of Hetzner's more specific IP address range, which took precedence in route selection under standard BGP. They also obtained a valid TLS certificate from Let's Encrypt, allowing connections to reach the attacker's server without triggering warnings. Hetzner initially accepted the unauthorized route and began announcing it at around 08:50 UTC on August 29, disrupting traffic for roughly 11 hours before cutting it off. The hijack returned at around 20:00 UTC, causing a second wave lasting ten hours.
During the incident window, a server had roughly a 72% chance of routing through the attacker's server. Softaculous warned users to reset passwords and check for any reused passwords or card details entered during the window. A malicious Virtualizor update package was delivered to a handful of installations, highlighting the importance of verifying update packages. Operators are advised to rotate and restrict API credentials, check for unknown SSH keys, and regenerate client-area API keys to mitigate potential risks.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.