hacker-news · Crawled Sep 6, 2026
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
13 IoCs
Read original article ↗
AI Summary
A zero-day vulnerability in Magento Open Source and Adobe Commerce, dubbed StyleSmuggler, is being actively exploited to achieve unauthenticated remote code execution and install persistent backdoors on e-commerce platforms. The attack chain leverages malicious input in log files and abuse of Magento's internal classes to execute a PHP dropper, which downloads and runs a malicious Rust-based implant. The backdoor runs under a disguised process name and establishes persistence via cron, with capabilities to read session data from Redis. No data exfiltration or lateral movement has been observed so far, but the threat is ongoing. Adobe has not yet released a patch or official advisory.
AI-extracted · verify before operational use
Indicators of Compromise 13 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 99[.]84[.]67[.]186 | Details → |
| IP | 88[.]216[.]72[.]181 | Details → |
| IP | 5[.]181[.]86[.]133 | Details → |
| Domain | 247[.]cdnflare[.]xyz | Details → |
| Filename | ~/.local/share/.gvfsd/gvfsd-user | Details → |
| Filename | ~/.local/share/.gvfsd/.gvfsd_<8hex>.lock | Details → |
| Filename | /tmp/.gvfsd_<8hex>.lock | Details → |
| Filename | /tmp/.kw_<random><random> | Details → |
| SHA-256 | e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 | Details → |
| SHA-256 | 8334b434fa3fe9f59cebe9609b11e0b1fd19d10212c45c705adec1902a1d06ef | Details → |
| SHA-256 | 251fabd50d7b18a8b5e1b3ef5d64e7198c17244778f6461fb1ab07f6169bf220 | Details → |
| Filename | var/report/ | Details → |
| Filename | var/log/system.log | Details → |