BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
| Source: Ars Technica AI
Tags: BGP hijacking, supply chain attack, Softaculous, Virtualizor, Hetzner, infrastructure security, code signing
Attackers exploited BGP routing weaknesses at Hetzner Online to hijack Softaculous IP addresses and push malware disguised as software updates — going undetected for 22 hours because Softaculous had never implemented code signing on its update packages.
Details
In a well-coordinated supply chain attack, unknown hackers abused lax BGP configuration at hosting provider Hetzner Online to seize control of IP addresses belonging to Softaculous, a UAE-based maker of web software installation tools and the Virtualizor server management platform. By controlling those IPs, attackers pushed malicious update packages to unsuspecting Virtualizor users — possible only because Softaculous had not implemented cryptographic code signing for updates. The attack unfolded in two bursts across a 33-hour window. After Hetzner reclaimed the address space the first time, attackers executed the same hijack again — this time taking nearly 10 hours to notice. Total undetected exposure spanned roughly 22 hours. Downstream transit peer Zet.net and hosting provider Nexon Host also share blame for failing to catch the malicious routing announcements. The incident is a textbook example of compounding failures: no BGP route origin validation, no RPKI enforcement, no code signing, and no real-time monitoring. BGP expert Ben Cartwright-Cox called the lapses silly and preventable. Practitioners running Virtualizor should treat every installation as potentially compromised and follow Softaculous' published remediation steps. This attack is directly relevant to AI infrastructure teams using managed hosting platforms — any software update mechanism lacking cryptographic verification is a potential supply chain vector.