BGP hijack turns software updates into malware delivery
Original: BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Why This Matters
BGP hijacking combined with absent code signing exposes critical infrastructure update pipelines to supply chain compromise.
Unknown attackers hijacked IP addresses belonging to Softaculous via a BGP routing attack, exploiting weak configurations at hosting provider Hetzner Online. Over a 33-hour window, malicious updates were pushed to Virtualizor servers. Softaculous confirmed update packages lacked cryptographic verification.
Unknown attackers executed a supply chain attack against Softaculous, a UAE-based developer of web software management platforms including Virtualizor. By exploiting lax routing security at Hetzner Online, the attackers performed a BGP hijack, seizing control of IP addresses Softaculous used to distribute software updates. During the 33-hour attack window, malicious update packages were served to Virtualizor installations whose traffic had been diverted.
Softaculous confirmed in a public advisory that its update client did not cryptographically verify update packages, meaning modified packages would not be rejected. The company stated it believes only a small number of servers were affected but cannot compile a definitive list, urging all Virtualizor server operators to treat their systems as potentially compromised.
Hetzner Online reclaimed the address space 12 hours after the initial hijack, but then stopped announcing the correct route, allowing attackers to execute the same hijack a second time. Hetzner took nearly 10 hours to respond to the second incident. Transit peer Zet.net also failed to detect the anomaly. Questions remain about hosting provider Nexon Host, whose infrastructure reportedly facilitated the malicious route announcement.
BGP expert Ben Cartwright-Cox described the collective failures as 'silly, preventable mistakes.' Hetzner Online, Softaculous, and Zet.net did not respond to requests for comment.