Hackers hijacked BGP routing for Softaculous update infrastructure and used it to push a malicious Virtualizor update to a small number of VPS installations. The incident affected traffic to the client/billing portal as well, prompting recommendations to check for the Java JRE update service and review credentials, keys, and account activity. #Virtualizor #Softaculous #BGP
Keypoints
- Attackers rerouted Hetzner-hosted IP addresses using BGP hijacking.
- Softaculous update requests were diverted to malicious servers.
- A malicious Virtualizor update reached a small number of installations.
- Admins were told to look for /etc/systemd/system/java-jre-update.service and audit systems.
- Softaculous released Virtualizor 3.2.9.9 and plans cryptographic package signing.