Hackers delivered malicious updates to some installations of Virtualizor, the virtual private server management software from Softaculous, after hijacking internet routing for part of the vendor’s update infrastructure, according to BleepingComputer. BleepingComputer reports that Softaculous issued an urgent notice saying the incident ran from 20:57 UTC on August 28 to 06:10 UTC on August 30. During that window, an attacker rerouted a block of Hetzner-hosted IP addresses through a Border Gateway Protocol hijacking attack, diverting traffic from Softaculous software update systems and its client and billing portal. Border Gateway Protocol is the internet’s routing system for telling networks where to send traffic. In a BGP hijack, a network falsely announces that it is the correct path to IP addresses controlled by another organization. If other networks accept that route, traffic can be sent to the wrong place, where an attacker may be able to redirect or alter it. Softaculous said the rerouting allowed attackers to deliver a malicious Virtualizor update package to a small number of installations that checked for updates while traffic was being diverted, according to BleepingComputer. The vendor described the impact as a handful of servers, not the overall Virtualizor user base. Virtualizor is a legacy web control panel used by hosting providers to create, sell, and manage virtual private servers. That makes update integrity especially important: compromise of management tooling can expose infrastructure operators that depend on the panel to administer customer VPS environments. Because update requests were redirected to the attacker, Softaculous said it does not have logs for those requests, BleepingComputer reports. The company told Virtualizor operators to check for the systemd service file /etc/systemd/system/java-jre-update.service. If the service is present, administrators were advised to rotate and restrict API credentials and audit for unauthorized SSH keys, new accounts, scheduled tasks, and outbound connections. Softaculous also advised users who accessed the client area or entered payment information during the incident window to reset passwords, review account activity, and monitor card statements, according to BleepingComputer. The company says routing has been restored and that a fraudulent certificate was reported for revocation. It also released Virtualizor version 3.2.9.9 on September 1 with a Security Analyzer tool in the admin panel. Softaculous said its investigation is still ongoing, with no indication so far that other products were affected, and plans to implement cryptographic signing for all software packages going forward and move to better infrastructure. Who benefits: Virtualizor operators benefit from the concrete indicators and mitigation steps Softaculous published, including the service-file check and the new Security Analyzer tool in version 3.2.9.9. Who's exposed: Hosting providers using Virtualizor are the most directly exposed, especially installations that checked for updates during the August 28–30 window. Users who logged into the Softaculous client area or entered payment details during that period also have follow-up account checks to perform.