Malicious Virtualizor Update Served via BGP Hijacking

A malicious update was quietly pushed to a small number of Virtualizor installations after a threat actor hijacked internet traffic and redirected it through attacker-controlled servers. The incident highlights the ongoing risk posed by BGP (Border Gateway Protocol) hijacking attacks, which can be used to compromise even the most secure systems.

Softaculous, a provider of applications for web hosting, offers an auto-installer tool for over 400 popular web applications, including its own Virtualizor control panel. Between August 28 and 30, a BGP hijack attack diverted traffic intended for Softaculous servers to attacker-controlled infrastructure, using a valid TLS certificate obtained through Let’s Encrypt.

The hijacker exploited the fact that some of Softaculous’ IP addresses are used not only for software updates but also for client area/billing services. A small number of Virtualizor installations checked for updates during this time and were served a malicious package. Fortunately, the company was able to restore legitimate traffic and has released an updated version of Virtualizor containing a mitigation tool.

The incident serves as a reminder that BGP hijacking attacks can be difficult to detect and can have devastating consequences. These attacks work by modifying the routing tables of internet service providers, allowing attackers to intercept and redirect traffic intended for a specific domain or IP address. In this case, the attacker obtained a valid TLS certificate, which enabled them to masquerade as Softaculous servers without triggering browser or client warnings.

Softaculous is urging all Virtualizor operators to check their systems for potential compromises, as it’s impossible to determine how many servers might have been affected. The company has provided a known indicator of compromise (IoC) and recommends that users reset their client-area passwords, review their account activity, and regenerate their API keys.

The incident highlights the importance of keeping software up-to-date and implementing robust security measures, such as code signing and cryptographic verification of update packages. It also underscores the need for regular system checks and monitoring to detect potential compromises.

In light of this incident, all Virtualizor operators should take immediate action by reviewing their systems and taking the recommended precautions. Users should also consider implementing additional security measures, such as two-factor authentication and logging of all updates and software installations. By staying vigilant and proactive in their security practices, users can minimize the risk posed by BGP hijacking attacks and other types of cyber threats.


Source: SecurityWeek — 2026-09-02