BGP Hijack Diverts Softaculous Traffic to Deliver Malicious Virtualizor Update
Brief
Attackers hijacked BGP routing for Softaculous last week and delivered a malicious Virtualizor update to a handful of hypervisor servers, according to a vendor incident report .
Hosting providers use Virtualizor to manage VPS nodes on KVM, Xen, LXC, OpenVZ, and Proxmox, and a single master can control hundreds of virtualization servers, placing a poisoned update high in the hosting stack. The product publicly lists hundreds of NOC partners, so a compromise here hits hosting infrastructure rather than a single website panel.
The hijack ran from about 20:57 UTC on 28 August 2026 until 06:10 UTC on 30 August. AS62390 (NexonHost) announced 162.
- 80. 0/24, a Hetzner block used by Softaculous update and billing systems, through AS6204 (Zet. net).
BGP Hijack Diverts Softaculous Traffic
Hetzner normally advertised only 162.
- 0.
