Magento StyleSmuggler Zero-Day Exploit: Linux Backdoor Deployment

www.news4hackers.com-magento-stylesmuggler-zero-day-exploit-linux-backdoor-deployment-magento-stylesmuggler-zero-day-exploit-linux-backdoor-deployment

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Overview of the Vulnerability

A previously unknown vulnerability in Magento and Adobe Commerce, tracked as StyleSmuggler, is being actively exploited to install a Linux-based backdoor. Security researchers at Sansec reported the first confirmed instance of this attack on September 4 against a system with the latest security patches applied. Adobe Enterprise Support confirmed working on a fix but has not yet disclosed a release timeline.

Exploit Mechanism

Magento, an open-source e-commerce platform developed by Adobe, is deployed on over 160,000 websites, including 14,000 of the top 1 million domains. The exploit leverages flaws in the platform’s template system to inject malicious PHP code, triggering a fabricated failed-payment notification that enables remote code execution.

Backdoor Characteristics

Successful exploitation results in the deployment of a lightweight Rust-based backdoor operating as a background process. The backdoor is disguised as system processes to evade detection. On older systems, it appears as [kworker/u:8:0], while newer versions mimic fc-cache and store copies in the ~/.cache/fontconfig directory.

Attack Persistence and Communication

Attackers establish persistence by adding a cron job set to execute every 30 minutes. Although no post-exploitation activity has been observed, the malware is capable of communicating with external infrastructure to receive commands. Earlier variants of the backdoor used TLS/WebSockets for command-and-control (C2) communication, but recent iterations mask traffic as Network Time Protocol (NTP) by sending UDP packets to port 123.

Network Evasion Techniques

These packets use domain names resembling legitimate time-syncing services, allowing the traffic to bypass network defenses. The malware also identifies the server’s public IP address through external APIs such as ipify, icanhazip, ident.me, and ipinfo.io. It checks the Linux TracerPid value to detect debugging tools; if tracing is detected, the backdoor installs but does not establish a connection.

Security Recommendations

Sansec advises monitoring for unusual “Payment Transaction Failed Reminder” email activity, as well as unexpected processes like kworker or fc-cache, suspicious cron entries, and temporary files. The organization recommends disabling GraphQL as a temporary mitigation until official patches are released.

Adobe’s Response and Mitigation

Adobe’s next scheduled security update, which may address the vulnerability, is set for September 8. The company has not yet responded to inquiries about whether the fix will include a solution for StyleSmuggler. Security simulations conducted by The Blue Report 2026 highlight that 37% of attacker actions are blocked when valid credentials are compromised, underscoring the importance of layered defenses.

Administrators are urged to review system logs for signs of unauthorized access and ensure all software is updated promptly. The exploit underscores the risks associated with unpatched e-commerce platforms and the need for continuous monitoring of infrastructure.

Conclusion

The StyleSmuggler vulnerability highlights the critical need for proactive security measures, timely patching, and vigilant monitoring of e-commerce platforms. Organizations must prioritize securing their infrastructure to mitigate the risks posed by zero-day exploits.



About Author

en_USEnglish