‘StyleSmuggler’ Zero-Day Exploited to Backdoor Adobe Commerce and Magento Stores

Threat actors are actively exploiting a zero-day vulnerability in Adobe Commerce and Magento to plant backdoors on online stores, according to research from cybersecurity firm Sansec. The flaw, which Sansec has named StyleSmuggler, affects Magento versions 2.4.7, 2.4.8 and 2.4.9, including stores already running the July and August 2026 security patches.

How the Attack Works

StyleSmuggler lets attackers inject PHP code into Magento’s template system by abusing the platform’s “styles” properties, evading detection in the process. Sansec describes a two-stage attack: the malicious code is first injected by generating a payment failure report, and Magento then executes that code when it sends out its standard “Payment Transaction Failed Reminder” email. No user interaction is required for the exploit to succeed.

Once triggered, the exploit deploys a backdoor written in Rust that connects to a command-and-control server and waits for further instructions. Sansec says the malware disguises its C&C communication as NTP server replies and transmits host information, including an agent ID, hostname, username, memory and disk usage, operating system version, uptime, root-access status and the implant’s version, along with the store’s public IP address.

Timeline and Detection

Sansec says it first found the campaign on Sept. 4 at 22:40 UTC and reproduced the exploit chain on clean installations within hours. The initial backdoor disguised itself as a process named “kworker/u:8:0”; a second variant that emerged on Sept. 6 disguises itself as “fc-cache.”

Because the exploit abuses a legitimate Magento email notification, Sansec recommends store operators watch for unexpected bursts of payment-failure reminder emails as a detection signal, while cautioning that legitimate declined payments can trigger the same notification. Adobe was expected to ship its regular monthly Patch Tuesday updates on Sept. 8, but as of this writing it was unclear whether that release would address StyleSmuggler specifically.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *