Operators of Virtualizor-based VPS platforms received malicious software updates after attackers hijacked the routing path for the control panel's update infrastructure. The incident demonstrates a rare but high-impact supply-chain vector targeting hosting automation tools.
What happened
Attackers performed a BGP hijack to redirect traffic intended for Virtualizor's official update servers to malicious endpoints under their control. When Virtualizor instances checked for updates, they instead downloaded and installed malware disguised as legitimate software. The source did not specify how long the hijack persisted or how many systems were affected.
Virtualizor, a web-based VPS management panel, is widely used by hosting providers to automate virtual server provisioning and administration. The attack did not compromise the software's source code or build process, but instead exploited the update delivery mechanism itself.
What we don't know yet
The source did not disclose the specific malware payload, the number of compromised systems, or whether the attackers targeted specific hosting providers. Timing of the attack remains unclear, as does the method used to gain initial access to the BGP routing infrastructure. No attribution to a known threat actor or group was provided.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 1 Sep 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story New story about BGP hijacking of Virtualizor updates not previously covered.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers this Virtualizor BGP hijacking attack.
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=491 slug=bgp-hijack-delivers-malicious-virtualizor-updates quick_read=1
-
Editor review — Approved
- Score: 85/100
- Factual grounding: The draft states 'The source did not specify how long the hijack persisted or how many systems were affected' — this is accurate, but the phrasing could imply the source explicitly mentioned these gaps. The source text does not mention these details at all, so the draft should clarify that these specifics are simply *not disclosed* rather than *not specified*.
- Style compliance: The standfirst ('Attackers rerouted update traffic to push malware via VPS control panel') is slightly redundant with the title. While not material, a tighter standfirst (e.g., 'BGP hijacking exposed hosting providers to malware via compromised updates') would better complement the headline.
- Audience relevance and notability: The draft does not explicitly state whether Virtualizor is industry-notable. While the source implies widespread use ('widely used by hosting providers'), the draft should briefly confirm Virtualizor's relevance to hosting/domains/DNS professionals (e.g., 'Virtualizor is a widely adopted VPS management panel among hosting providers').
- Quote integrity: No blockquotes are used, which is correct as the source does not provide a verbatim quote suitable for attribution. However, the draft could benefit from a paraphrased attribution (e.g., 'According to BleepingComputer...') to clarify the source of claims, though this is not a material issue.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Reused library image reused image #234
- Linking related stories — Linked 5 relations from 425 candidates
- Publishing — Published bgp-hijack-delivers-malicious-virtualizor-updates
- Mastodon — Posted https://mstdn.social/@hostingpaper/117196585780407314




Discussion · coming soon
Be the first to join the thread when community discussion launches.