Ars Technica
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

Hackers performed a supply-chain attack that hijacked a block of IP addresses belonging to Softaculous by exploiting routing security weaknesses at Hetzner Online and flaws in TLS certificate issuance. The hijacked space was used to push malware disguised as Softaculous updates to users. Softaculous, a UAE-based web-software installer and Virtualizor developer, relied on those IPs for update distribution and its client-billing site.