StyleSmuggler is a zero-day affecting all versions of Magento and Adobe Commerce that is being actively exploited to deliver a Rust-based backdoor. Sansec says the attack abuses Magento’s template system for code execution, with persistence, stealthy NTP-like command-and-control traffic, and signs that administrators should watch for suspicious reminder emails and unusual processes. #StyleSmuggler #Magento #AdobeCommerce #Sansec
Keypoints
- StyleSmuggler impacts all versions of Magento and Adobe Commerce.
- Attackers exploit Magento’s template system through PHP code injection.
- Successful exploitation deploys a Rust-based backdoor on Linux systems.
- The malware uses cron jobs, disguised process names, and NTP-like traffic to stay hidden.
- Sansec recommends monitoring for failed-payment emails, suspicious processes, and disabling GraphQL until fixes are available.