bleeping-computer · Crawled Sep 7, 2026
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
7 IoCs
Read original article ↗
AI Summary
A zero-day vulnerability dubbed 'StyleSmuggler' in Magento and Adobe Commerce is actively exploited to achieve remote code execution and deploy a Rust-based Linux backdoor. The exploit leverages PHP code injection via Magento's template system to trigger malicious activity, including the creation of a disguised backdoor process and a persistent cron job. The backdoor communicates with C2 infrastructure using spoofed NTP traffic on UDP port 123 to evade detection, and checks for tracing before beaconing. Adobe has not yet released a patch, but mitigation advice includes disabling GraphQL.
AI-extracted · verify before operational use