Softaculous and Virtualizor suffered a 33-hour BGP hijack that diverted traffic through an attacker-controlled server, enabling malware-laced Virtualizor updates and potential credential and payment data exposure for customers using affected systems. The attacker announced a more specific Hetzner IP range used by Softaculous, which many networks accepted, and obtained a valid Let's Encrypt TLS certificate, preventing browser warnings and allowing hijacked connections to appear legitimate during two hijack waves. Softaculous urges password resets, payment card checks, and Virtualizor server inspections, including hunting for a malicious systemd unit, rotating API credentials, reviewing SSH access, and preserving evidence as investigations continue and compromised sessions are invalidated.
This update represents a notable development in the Board sector. Organizations and founders tracking this space should evaluate potential strategic and technical implications on their operations.