Softaculous’ Virtualizor users were served malicious software updates for two days after a threat actor diverted internet traffic to attacker-controlled servers.
A provider of applications for web hosting, Softaculous offers an auto-installer tool for over 400 popular web applications. Virtualizor is its web-based Virtual Server (VPS) management control panel.
Between August 28 and August 30, a block of Softaculous IP addresses was hit by a BGP hijack attack: a threat actor used a technically valid TLS certificate for the company’s domains to divert traffic to attacker infrastructure.
The IP addresses affected by the BGP hijack, Softaculous says, were used for software updates, client area/billing, and other services.
“We have confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted. This affected a handful of servers rather than the general Virtualizor user base,” the company says.
Softaculous encourages all Virtualizor operators to check for potential compromises, as it cannot tell how many servers might have been affected. The malicious traffic never reached the company’s logs.
“We have not identified a malicious package for any other product; that investigation is ongoing,” the company notes, adding that it has fully restored traffic to its legitimate servers.
The BGP hijack started at approximately 20:57 UTC on 28 August 2026, when AS62390 (NexonHost) began announcing a portion of German web hosting provider and data center operator Hetzner’s address space, including IP addresses for Softaculous systems.
“This announcement was more specific than Hetzner’s normal announcement of the surrounding block (162.55.0.0/16), so under standard BGP route selection it took precedence on every network that accepted it. The announcement retained AS24940 (Hetzner) on the AS path as the apparent origin,” Softaculous notes.
Next, the threat actor obtained a valid TLS certificate for Softaculous domains from Let’s Encrypt, “because the certificate authority’s automated domain-ownership validation was also routed through the hijack,” the company explains.
The hijacker could then redirect traffic to their server without triggering a browser or client certificate warning.
According to Softaculous, only a small number of Virtualizor instances were served a malicious package: those that checked for an update and completed it during the hijack window. The traffic was intermittently diverted for 22 hours (and almost no diversion occurred during an 11-hour window mid-incident).
“Our product update clients did not yet cryptographically verify update packages, so a modified package would not have been rejected on that basis. We believe only a small number of servers were actually affected, but we cannot produce a definitive list, so please treat every Virtualizor server as in scope for checks,” the company notes.
Softaculous has provided a known indicator of compromise (IoC) and encourages users to reset their client-area passwords, review their account activity, and regenerate their API keys.
The company has released a version of Virtualizor 3.2.9.9 containing a mitigation tool for known exploits and is implementing a code signing mechanism for all packages.
Related: Rust Supply Chain Attack Linked to North Korean Hackers
Related: Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Related: Fortune 500 Companies Hit in Azure Data Theft Campaign


