SECURITY Signal 51
BGP hijack diverted Softaculous traffic for 33 hours, delivered malicious Virtualizor updates
A 33-hour BGP hijack diverted Softaculous traffic through an attacker-controlled server that held a valid Let's Encrypt TLS certificate, enabling delivery of malicious Virtualizor update packages to installations that lacked cryptographic package verification.
The incident shows that BGP hijacking combined with automated certificate issuance can fully bypass TLS protections, and that software update mechanisms without cryptographic verification remain critically exposed to supply-chain compromise. Any Virtualizor operator whose server was active during the incident window should assume potential compromise, since no definitive list of affected installations exists.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
An attacker announced a more specific IP range than Hetzner's normal advertisement, causing standard BGP route selection to divert traffic to their server across two waves totaling roughly 33 hours.
The attacker obtained a valid Let's Encrypt TLS certificate because automated domain-ownership validation was also routed through the hijack, preventing certificate warnings on affected connections.
Virtualizor's update client did not cryptographically verify packages, allowing a malicious update to be delivered to an unknown number of installations with no definitive list of affected servers.
THE CLUSTER