StyleSmuggler zero-day hijacks Magento stores with no patch ready

An unpatched flaw named StyleSmuggler is letting attackers backdoor Magento and Adobe Commerce stores with no login.

CSBadmin
2 Min Read

Magento Open Source and Adobe Commerce stores are under active attack through a vulnerability with no patch, no CVE identifier, and no official advisory yet. Sansec, the e-commerce security firm that found the hole and christened it StyleSmuggler, says real-world attacks began September 4 and that it went public early because shops were being hit live.

The hole hands anyone without credentials the ability to run code on the store’s server and drop a persistent backdoor. Sansec reports all current builds are exposed, 2.4.9 included, and reproduced the attack end to end on fresh 2.4.7, 2.4.8 and 2.4.9 installs. One early victim was running a fully patched 2.4.6-p15 release.

The exploitation unfolds in two phases. Phase one tucks PHP into a file Magento generates itself, like a failure report or log. Phase two fires the built-in Payment Transaction Failed Reminder email, so the code executes while the message is being rendered. The implant disguises itself as a kernel thread named [kworker/u:8:0], hides its binary under the site user’s home directory, and re-registers every five minutes through the cron spool.

Hosting provider Disrex Group handled two breached shops and confirms the speed: both fell inside the eight-hour gap between the first spotted attack and any defense, both fully patched. Patch status was irrelevant, it stressed.

Adobe had published nothing as of September 6; its next scheduled security release lands September 8 with no confirmation the bug will be covered. Sansec’s interim advice for stores without its Shield product: disable GraphQL, which most classic and Hyva storefronts do not need.

Merchants should treat any unexpected burst of failed-transaction reminder emails as a reason to investigate and check both var/report and var/log for the X_TRACE_ marker before assuming the site is clean.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.