Softaculous and Virtualizor users urged to reset passwords after 33-hour BGP hijack
A 33-hour BGP hijacking event rerouted traffic from Softaculous and its Virtualizor control panel to a malicious server, prompting the vendor to tell customers to change credentials and check for compromised updates.
From roughly 20:57 UTC on August 28 to early August 30, a BGP hijack redirected traffic destined for Softaculous and its Virtualizor VPS management panel to an attacker-controlled server by announcing a more specific Hetzner IP range. The hijacker obtained a legitimate Let's Encrypt certificate, so connections did not raise security warnings. Softaculous reported the intrusion to Hetzner, which later re-announced the correct route, reducing the diversion for about 11 hours before a second wave began and finally ended by early August 30.
The vendor estimates a 72 percent chance that any given server saw the hijacked route and advises all customers to reset passwords, invalidate sessions, and scrutinize their systems for a malicious systemd unit at /etc/systemd/system/java-jre-update.service. A malicious Virtualizor update package was delivered to a few installations, though the exact number is unknown. Softaculous also urges operators to rotate API credentials, audit SSH keys, and monitor outbound connections, while the investigation continues.
Why it matters
The incident shows how BGP hijacks can expose web-hosting services to credential theft and malware distribution.
In this story
