Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
StyleSmuggler is a zero-day affecting all versions of Magento and Adobe Commerce that is being actively exploited to deliver a Rust-based backdoor. Sansec says the attack abuses Magento’s template system for code execution, with persistence, stealthy NTP-like command-and-control traffic, and signs that administrators should watch for suspicious reminder emails and unusual processes. #StyleSmuggler #Magento #AdobeCommerce #Sansec

Keypoints

  • StyleSmuggler impacts all versions of Magento and Adobe Commerce.
  • Attackers exploit Magento’s template system through PHP code injection.
  • Successful exploitation deploys a Rust-based backdoor on Linux systems.
  • The malware uses cron jobs, disguised process names, and NTP-like traffic to stay hidden.
  • Sansec recommends monitoring for failed-payment emails, suspicious processes, and disabling GraphQL until fixes are available.

Read More: https://www.bleepingcomputer.com/news/security/magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor/