“We have confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted,” Softaculous said.
How the hijack unfolded and the timeline
Softaculous reported that between 20:57 UTC on August 28 and 06:10 UTC on August 30 an attacker rerouted a block of Hetzner-hosted IP addresses in a Border Gateway Protocol (BGP) hijacking. Because the fraudulent route caused traffic intended for Softaculous update systems and the client/billing portal to be diverted to attacker-controlled infrastructure, update requests during that window were received and answered by the threat actor rather than by the vendor.
Scope and impact on Virtualizor installations
Virtualizor is a legacy web control panel from Softaculous used by hosting providers to create, sell, and manage virtual private servers (VPS). Softaculous says the incident allowed the delivery of a malicious Virtualizor update package to a small number of installations — “a handful of servers” rather than the general Virtualizor user base. Because the update checks and subsequent downloads were handled by the attacker’s diverted infrastructure, Softaculous does not have server-side logs for those redirected requests.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildActions Softaculous recommends and the vendor’s response
Softaculous advises Virtualizor operators to check for the presence of the service file /etc/systemd/system/java-jre-update.service and, if it is found, to rotate and restrict API credentials and audit systems for unauthorized SSH keys, accounts, scheduled tasks, and outbound connections. The company also told users who accessed the Softaculous client area or entered payment information during the incident window to reset passwords, review account activity, and monitor card statements.
On September 1 Softaculous released Virtualizor version 3.2.9.9, which includes a “Security Analyzer” tool in the admin panel. The vendor says routing has been restored, the fraudulent certificate was reported for revocation, and it plans to implement cryptographic signing for all software packages going forward and to migrate to better infrastructure.
Technical note: what a BGP hijack does to software updates
The advisory reiterates how BGP hijacking works: a network operator falsely announces a route to IP addresses belonging to another organization and other networks may accept that fraudulent route as the preferred path. An attacker that receives traffic this way can modify or redirect it to malicious destinations. In this incident, that capability allowed attackers to respond to update checks with a malicious package for some Virtualizor installations.
The vendor’s post-incident steps — reporting the fraudulent certificate for revocation, releasing a patched version, and planning cryptographic signing — are concrete mitigations aimed at restoring route integrity and ensuring update authenticity.
What this means for hosting providers, Virtualizor operators, and end users
- Hosting providers: the incident involved rerouting a block of Hetzner-hosted IP addresses in a BGP hijack. Providers that operate or peer with affected networks will be watching route announcements and the integrity of update-delivery paths and may need to coordinate with network operators and affected vendors to confirm routes and certificate revocation.
- Virtualizor operators: Softaculous’s checklist is specific — search for /etc/systemd/system/java-jre-update.service, rotate and restrict API credentials, and audit for unauthorized SSH keys, accounts, scheduled tasks, and outbound connections. Operators should also upgrade to Virtualizor 3.2.9.9 to obtain the Security Analyzer and other vendor fixes.
- End users and customers who accessed the client area or entered payment information during the incident window: reset passwords, review account activity, and monitor card statements as recommended by Softaculous.
Softaculous says its investigation is ongoing and that there are no indications other products were impacted. The incident underscores two linked facts the vendor highlighted: BGP-route manipulation can let attackers interpose on distribution channels, and when legitimate credentials or valid routes are abused, prevention effectiveness drops sharply. The vendor’s immediate steps — revoking the fraudulent certificate, restoring routing, releasing 3.2.9.9 with a Security Analyzer, and committing to cryptographic signing for future packages — set clear technical priorities for closing the specific gap exploited in this case.
Source: BleepingComputer — Hackers push malicious Virtualizor update in BGP hijacking attack




