Routing & Security

Virtualizor reports package-signing changes after August BGP hijack

A 29 September vendor update reports package and API-response signing after an August routing hijack. The incident illustrates the limits of origin validation.

BYOIP.info EditorialChange dated

What changed

In a 29 September update to its incident report, Virtualizor's vendor said it had begun signing packages across its software products, signing API responses and placing its mirrors behind Cloudflare.

The update follows a BGP hijack affecting Softaculous infrastructure on 28-30 August 2026. The vendor confirmed that an attacker delivered a malicious Virtualizor update to a small number of installations. It provides checks for operators in the original incident notice.

This is a remediation follow-up to the August incident. It is not a report of a new September attack.

What the routing analysis showed

Doug Madory's analysis describes an unauthorised, more-specific route with the legitimate origin ASN appended to its AS path. The covering ROA also permitted the longer prefix. As a result, the hijacked route could pass route origin validation.

That distinction matters: an RPKI-valid origin does not authenticate every network in the path. The analysis describes subsequent tightening of several ROAs and the addition of an ASPA record, while noting remaining permissive ROAs at the time of its update.

Why it matters for BYOIP teams

The operational lesson for portable address space is to review both authorisation and observation. An expected origin ASN is useful evidence, but a newly appearing sub-prefix or an unexpected upstream path can still warrant investigation.

The vendor's signing changes address software-delivery integrity. They should not be presented as proof that routing attacks are now impossible, and moving mirrors behind another provider is not a universal guarantee against hijacking.

What to check

  • If you operate Virtualizor, follow the vendor's incident-specific assessment and remediation guidance.
  • Review ROA prefix-length permissions against the routes actually intended for announcement.
  • Include unexpected more-specific routes and upstream-path changes in routing-monitoring reviews.
  • Identify critical update services and who is responsible for investigating suspicious delivery or routing behaviour.

For standards context, see our ASPA status check.

Sources

  1. Security Incident - BGP Hijacking

    Virtualizor · published 31 Aug 2026 · checked 6 Oct 2026

  2. Latest BGP Hijack Targets Hosting Software Vendor

    Doug Madory, Kentik Blog · published 2 Sept 2026 · checked 6 Oct 2026

Related resources

Topicsbgprpkivirtualizorrouting-security