Hackers hijacked internet routing to push a poisoned Virtualizor update
Softaculous says attackers rerouted its update servers for 33 hours, delivering a malicious update to a small number of hosting providers running Virtualizor.

Key points
- Attackers hijacked internet routing for Softaculous update servers between 20:57 UTC on 28 August and 06:10 UTC on 30 August 2025.
- A malicious Virtualizor update reached a small number of installations that checked for updates during the 33-hour window.
- Softaculous released Virtualizor 3.2.9.9 on 1 September with a new Security Analyzer tool in the admin panel.
- Customers who used the Softaculous client area or entered card details during the window are told to reset passwords and monitor statements.
- The vendor plans to add cryptographic signing to all future software packages.
Criminals broke into the update system for Virtualizor, a control panel that hosting companies use to sell and manage virtual private servers, and pushed out a booby-trapped update to some of its customers.
The attack, first reported by BleepingComputer, worked by tricking the internet itself. For about 33 hours, traffic meant for the vendor's servers was quietly steered to servers run by the attacker.
Softaculous, the company behind Virtualizor, has published an urgent notice confirming what happened.
How did the hackers get in?
They used a technique called BGP hijacking. BGP, short for Border Gateway Protocol, is the system internet providers use to tell each other which routes lead to which addresses. Think of it as the internet's road signs.
An attacker put up fake road signs pointing to a block of Softaculous IP addresses hosted at Hetzner, a large European hosting firm. Other networks believed the fake route and started sending traffic the wrong way.
That traffic included requests from Virtualizor servers asking for software updates, plus visits to the Softaculous client and billing portal. The window ran from 20:57 UTC on 28 August 2025 to 06:10 UTC on 30 August 2025.
During that time, any Virtualizor server that phoned home for an update could receive a poisoned package instead of the real one.
How many customers were affected?
Softaculous says only a small number. In its notice, the vendor states: "We have confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted. This affected a handful of servers rather than the general Virtualizor user base."
Because the requests never reached the real servers, Softaculous has no logs of exactly who received the bad update. Administrators have to check for themselves.
What should Virtualizor operators check?
Softaculous is telling admins to look for a specific file on their systems:
| Item | Value |
|---|---|
| File to check | /etc/systemd/system/java-jre-update.service |
| Attack window start | 28 Aug 2025, 20:57 UTC |
| Attack window end | 30 Aug 2025, 06:10 UTC |
| Fixed version | Virtualizor 3.2.9.9 (released 1 Sep 2025) |
If that file is present, the server should be treated as compromised. The vendor recommends rotating API credentials, tightening what those credentials can do, and checking for SSH keys, user accounts, scheduled tasks and outbound network connections that should not be there.
SSH keys are digital keys that let someone log in to a server without a password. Attackers often leave their own behind so they can return later.
What about ordinary customers?
Anyone who logged in to the Softaculous client area, or typed in payment details during the attack window, should reset their password and keep an eye on their card statements. If the traffic was flowing through the attacker's servers, the attacker could have captured what was typed.
Softaculous says routing has now been restored and the fraudulent TLS certificate the attacker used has been reported for revocation. A TLS certificate is the small file that proves a website is really who it says it is. The company is also promising to cryptographically sign all future software packages, which would let customers verify an update genuinely came from Softaculous before installing it.
The investigation continues. Softaculous says no other products appear to have been touched.



