BGP hijack pushed fake Softaculous updates to hosting networks, Ars Technica reports
A BGP hijack of Softaculous update addresses pushed malware to hosting networks, exposing routing security and TLS certificate weaknesses.
The attackers exploited weaknesses in the routing security setup of Hetzner Online and the process for obtaining valid TLS certificates, according to the report. Those lapses allowed a Border Gateway Protocol hijack that gave the hackers control over IP addresses assigned to Softaculous, a UAE-based maker of web software installation and management tools and the developer of Virtualizor, a management platform for virtualized environments. Softaculous used those addresses to issue updates and to host its client and billing site.
With control over the hijacked space, the attackers used the addresses to push malware masquerading as legitimate updates to unsuspecting users. Ars Technica said the operation was coordinated at multiple levels, taking advantage of mistakes in Hetzner Online's routing security and in the TLS certificate process, and it described the result as a supply chain infection because the hijacked space belonged to a trusted software vendor.