33 hours of BGP hijacking on Softaculous: when Internet routing becomes a weapon

Cybersecurity Sep 2, 2026Add to bookmarks

33 hours of BGP hijacking on Softaculous: when Internet routing becomes a weapon
Illustration : Momiji Shirogane

For 33 hours, traffic to Softaculous—the web application installer used by millions of cPanel/Plesk hosting providers—was silently redirected via a BGP hijack attack. A major exposure window for a critical infrastructure in global web hosting.

What: 33 hours of BGP hijacking

For 33 hours, network traffic destined for Softaculous—one of the most widely used web application installers in shared hosting (WordPress, Joomla, Drupal, and 400+ other apps)—was silently redirected to malicious servers.

The attack exploited a structural flaw in the BGP (Border Gateway Protocol), the protocol that manages routing between autonomous systems (AS) on the Internet. The attacker announced IP prefixes belonging to Softaculous via an intermediate AS, deceiving routers in part of the Internet backbone. Legitimate connections were routed to a server under adversarial control—potentially for man-in-the-middle attacks, credential harvesting, or distribution of altered code.

Who is impacted

Softaculous is used by thousands of hosting providers (cPanel, Plesk, DirectAdmin) to install and update web applications. If you manage shared hosting or resell cPanel hosting, your clients likely use Softaculous.

During these 33 hours, any update or installation triggered via Softaculous could have pointed to a compromised server. The main risk: code injection in distributed packages.

What to do now

  • Reset Softaculous credentials and verify the integrity of applications installed or updated during the incident window
  • Enable RPKI (Resource Public Key Infrastructure) on your network infrastructure—the gold standard defense against BGP hijacking
  • Monitor BGPmon / RIPE RIS to detect abnormal announcements of your own IP prefixes
  • Search for malicious packages in your Softaculous installations (direct advice from Softaculous to its customers)

BGP: The Achilles' heel of the Internet

BGP dates back to 1989 and lacks native authentication mechanisms. Any operator with access to an AS can, by mistake or malice, announce IP prefixes that do not belong to them. RPKI (Resource Public Key Infrastructure) enables cryptographic validation of route announcements, but adoption remains partial despite notable progress in recent years.

What to do now

  1. Identify whether any Softaculous installations or updates occurred during the incident window
  2. Reset credentials and verify installed packages
  3. Enable RPKI (BGP route origin validation) on your infrastructure
Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

15 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information