A malicious Virtualizor update was delivered to a small number of servers after attackers hijacked internet routing for part of Softaculous’s update infrastructure, the software company has warned.
Virtualizor is used by hosting providers to create and manage virtual private servers. Softaculous said the incident involved a block of IP addresses hosted by Hetzner, with traffic diverted between 20:57 UTC on 28 August and 06:10 UTC on 30 August.
The attackers used a Border Gateway Protocol (BGP) hijacking technique, falsely advertising routes to addresses belonging to Softaculous. This caused some update requests, as well as traffic to the company’s client and billing portal, to be sent to servers controlled by the attackers.
Softaculous said a malicious Virtualizor package was supplied to “a small number of installations that checked for updates while their traffic was being diverted”. The company described the affected systems as “a handful of servers rather than the general Virtualizor user base”.
Because the requests were redirected before reaching Softaculous, the company said it does not have complete logs showing which installations received the tampered package. Its investigation remains under way.
Advice for Virtualizor administrators
Administrators have been urged to check whether their systems contain the service /etc/systemd/system/java-jre-update.service. Its presence could indicate that a machine was affected during the attack.
Softaculous recommends rotating and restricting API credentials, while also checking for unauthorised SSH keys, unfamiliar user accounts, unexpected scheduled tasks and suspicious outbound network connections.
Users who logged into the Softaculous client area or entered payment details during the affected period have been advised to change their passwords, review account activity and monitor their card statements.
Softaculous said there was no indication that any of its other products had been compromised. It has restored normal routing and reported the fraudulent certificate used in the incident for revocation.
Version 3.2.9.9 of Virtualizor was released on 1 September with a new Security Analyzer tool in the administration panel. The company also said it intends to introduce cryptographic signing for all software packages and move its update systems to more robust infrastructure.
