A zero-day vulnerability called StyleSmuggler is being exploited against all versions of Magento and Adobe Commerce to deploy a Linux backdoor.
The first known exploitation was recorded on September 4 against a site running the latest security updates. Sansec said Adobe Enterprise Support was working on a fix but had not provided a release timeline. Adobe had not released a fix when the report was published.
Magento is installed on more than 160,000 websites, including 14,000 of the top 1 million sites. The observed exploit abuses Magento’s template system through PHP code injection to generate a fake “failed-payment” email and trigger code execution.
The resulting Rust-based backdoor runs as a background process disguised as kworker/u:8:0. Newer versions use fc-cache, copy the file to ~/.cache/fontconfig/fc-cache, and add a cron job that repeats every 30 minutes. The malware can receive commands from remote infrastructure.
Earlier samples used TLS/WebSockets, while newer versions disguise traffic as Network Time Protocol (NTP), sending UDP packets to port 123. The malware can also detect tracing through Linux’s TracerPid value and avoid beaconing when tracing is active.
Sansec recommends monitoring for unexpected “Payment Transaction Failed Reminder” emails, suspicious processes, cron entries, and temporary files. Adobe’s next scheduled security release is September 8. Until a fix is available, Sansec recommends disabling GraphQL.
Comments
0No comments yet. Be the first to comment.