BGP Hijack Delivers Malicious Virtualizor Update to Limited Installations

Attackers successfully hijacked BGP routing for Softaculous's update infrastructure, redirecting update requests to malicious servers and delivering a tainted Virtualizor VPS management software update to a small number of installations. The incident occurred between August 28 and August 30, when a block of Hetzner-hosted IP addresses was rerouted, diverting traffic from both update systems and the client billing portal. Softaculous confirmed that only installations that checked for updates during the diversion window received the malicious package, affecting a handful of servers rather than the broader user base.

The vendor recommends Virtualizor operators check for the presence of a suspicious systemd service and rotate API credentials, audit unauthorized SSH keys and accounts, and review outbound connections. Customers who accessed the client area or entered payment details during the incident should reset passwords and monitor financial statements. Routing has been restored, and a new Virtualizor version with a Security Analyzer tool was released, with Softaculous planning cryptographic signing for future packages. No other products were impacted, and the investigation remains ongoing. The vendor lacks logs due to traffic redirection to attacker-controlled infrastructure. The fraudulent certificate used in the attack has been reported for revocation. Admins should prioritize auditing affected systems for signs of compromise. The incident underscores the risks of BGP hijacking for software supply chain integrity. Softaculous is implementing cryptographic signing for all future software packages. The vendor is also migrating to improved infrastructure to prevent similar attacks. Users should verify they are running the latest Virtualizor version. The Security Analyzer tool helps administrators detect potential compromise indicators. Regular audits of system services and credentials are recommended for all Virtualizor operators.

Read more...

Read More

Got Something To Say?

Your email address will not be published.