Magento’s StyleSmuggler Zero-Day Exploited to Deploy Linux Backdoor, Leaving Thousands of Sites Vulnerable
A severe security vulnerability known as StyleSmuggler has been discovered affecting all versions of Magento and Adobe Commerce. This zero-day exploit allows attackers to deploy a backdoor on compromised servers, leaving thousands of websites exposed. According to e-commerce security company Sansec, the vulnerability is being actively exploited in attacks, with the first incident recorded on September 4 on a target running the latest security updates.
The StyleSmuggler exploit takes advantage of Magento’s template system through PHP code injection, generating a fake “failed-payment” email that triggers code execution. Once successful, it installs a small Rust-based backdoor as a background process, disguised as [kworker/u:8:0] on older versions and fc-cache on newer ones. The attacker also adds a cron job configured to repeat every 30 minutes for persistence.
The researchers at Sansec have observed that the malware can communicate with remote infrastructure and receive commands. While no follow-on activity has been seen, the backdoor’s capabilities include sending UDP packets to port 123 and using hostnames that resemble time-syncing infrastructure to mask malicious traffic as Network Time Protocol (NTP). This allows the attacker to evade detection by firewalls.
Sansec warns that an unexpected surge of Magento “Payment Transaction Failed Reminder” emails may indicate exploitation. Website administrators are advised to monitor for ‘kworker’ or ‘fc-cache’ processes, suspicious cron entries, and temporary files. If there is suspicion of compromise, it is recommended to rotate Magento credentials immediately.
At the time of writing, Adobe has not released fixes for StyleSmuggler, but the company’s next scheduled security release is tomorrow, September 8. Until then, Sansec recommends disabling GraphQL as a mitigation measure. This will help prevent further exploitation until patches are made available.
In light of this incident, it’s essential for website administrators to take proactive measures to protect their sites from zero-day exploits like StyleSmuggler. Regularly reviewing security updates and applying patches promptly can significantly reduce the risk of compromise. Moreover, monitoring for suspicious activity, such as unusual email traffic or background processes, is crucial in detecting potential attacks early on. By staying vigilant and taking these steps, website administrators can help ensure the security and integrity of their online presence.
Source: Bleeping Computer — 2026-09-07