"The unauthorized route was initially 'accepted by essentially every internet vantage point that receives it,'" Softaculous reported — and for roughly 33 hours the consequence was more than a routing anomaly: diverted traffic, a valid TLS certificate issued to the attacker, and at least a handful of compromised Virtualizor installations.
How the BGP hijack worked and unfolded
Beginning at around 20:57 UTC on August 28, an unrelated network announced a more-specific block of Hetzner IP addresses used by Softaculous, causing some traffic intended for the vendor's systems to be diverted to an attacker-controlled server. Under standard BGP route selection the more-specific route takes precedence wherever accepted, which is how the diversion succeeded.
Softaculous said the unauthorized route "flapped" rather than remaining continuously available, but that it was widely accepted when present. The vendor reported the problem to Hetzner at about 08:50 UTC on August 29. Hetzner — identified in Softaculous's timeline as an upstream German hosting provider — then began directly announcing the same more-specific range, which the vendor says cut the observed diversion to almost zero for roughly 11 hours. The attacker resumed the unauthorized announcement at around 20:00 UTC on August 29, producing a second wave that lasted roughly ten hours before the route was withdrawn between 05:50 and 06:10 UTC on August 30.
Softaculous estimates that, while either wave was active, a given server had roughly a 72 percent chance of being on a network that routed the affected address range through the attacker. That estimate is based on the proportion of RIPE routing collector peers carrying the hijacked route; Softaculous cautioned it is not a measure of intercepted traffic volume.
Which services were hit
The hijack affected "a number of Softaculous systems," including Virtualizor's software update endpoint and Softaculous's client and billing site. Because the attack also routed Let's Encrypt's automated domain-ownership validation through the hijack, the attacker was able to obtain a valid TLS certificate and serve pages without triggering certificate warnings.
Softaculous confirmed that a malicious Virtualizor update package was delivered to a handful of installations whose update checks passed through the attacker's server. The vendor said the affected downloads never reached its own logs, and therefore it "cannot produce a definitive list" of infected installations. It also said it has not identified malicious packages targeting Backuply, Softaculous, SitePad, Webuzo, or its other products, while its investigation continues.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleMalicious update indicator and immediate remediation steps
Softaculous identified a concrete indicator of compromise: a systemd unit located at /etc/systemd/system/java-jre-update.service. Operators who find that unit are advised not to delete it immediately but to contact the vendor so evidence can be preserved.
The vendor acknowledged a security design shortcoming: "Our product update clients did not yet cryptographically verify update packages, so a modified package would not have been rejected on that basis." As immediate mitigations, Softaculous told Virtualizor operators to treat their servers as in scope for checks (not necessarily as already compromised), rotate and restrict API credentials, check for unknown SSH keys and accounts, inspect scheduled tasks and outbound connections, and regenerate client-area API keys. Softaculous is also invalidating client-area sessions created during the incident window.
Separately, anyone who logged into the Softaculous client area during the incident window is urged to reset that password immediately and anywhere it was reused. Customers who entered card details during the same window should review their statements; Softaculous said it does not process cards on its own servers and instead uses payment gateways, but acknowledged an affected session may have been diverted before reaching those gateways.
What this means for Virtualizor operators, payment holders, and Hetzner
- Virtualizor operators: Treat each server as in scope for forensic and credential checks, rotate API keys and passwords, and look specifically for the systemd unit at /etc/systemd/system/java-jre-update.service; preserve evidence by contacting Softaculous before removing suspected indicators.
- Payment holders and client-area users: Reset client-area passwords used during the incident window, review bank and card statements for transactions made while sessions may have been intercepted, and note that Softaculous uses payment gateways rather than hosting card data on its own servers.
- Hetzner (upstream provider): Softaculous's timeline records that Hetzner began directly announcing the same more-specific address range after the vendor reported the hijack, which briefly reduced diversions; the hijack later reappeared and was withdrawn only after the second wave ended on August 30.
Softaculous has not disclosed how many customers downloaded the malicious update or how many credentials may have been exposed, saying only that confirmed infections are "a handful of servers rather than the general Virtualizor user base." The combination of a more-specific BGP announcement, automated CA validation being routed through the attacker, and update clients that lacked cryptographic verification produced a brief but potent chain: diverted traffic, valid TLS that masked the interception, and a path for a modified update to be accepted.
The immediate next facts to watch are straightforward and narrow: whether Softaculous produces a definitive list of affected installations, whether additional malicious packages are discovered for other Softaculous products, and how broadly operators find the java-jre-update.service indicator. Until those facts are confirmed, Virtualizor operators and clients remain obliged to assume exposure and act accordingly.




