
A zero-day vulnerability called “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is used in backdoor deployment attacks.
The first exploit incident was recorded on September 4th on a target running the latest security updates.
E-commerce security company Sansec says Adobe Enterprise Support confirmed earlier today that it is working on a fix, but did not provide a timetable for its release.
Magento is a popular open source e-commerce platform from Adobe, installed on more than 160,000 websites, including 14,000 of the top 1 million sites.
Linux backdoor
The Sansec exploit observed in the wild abuses Magento’s templating system by injecting PHP code to generate a fake “payment failed” email that triggers code execution.
A successful exploit installs a small Rust-based backdoor as a background process masquerading as (kworker/u:8:0). Newer versions mask the process as fc-cache and copy it to ~/.cache/fontconfig/fc-cache.
According to Sansec researchers, the attacker also added a cron job configured to repeat every 30 minutes for persistence.
Although Sansec does not monitor any subsequent activity, the malware can communicate with remote infrastructure and receive commands.
The researchers note that earlier samples of the backdoor used TLS/WebSockets to communicate with the Command and Control (C2) address, while newer versions masked their traffic as Network Time Protocol (NTP).
They send UDP packets to port 123 and use hostnames that resemble time synchronization infrastructure, helping to mask malicious traffic such as NTP and passing through firewalls.
The malware also determines the server’s public IP using services including ipify, icanhazip, ident.me, and ipinfo.io, and checks Linux’s TracerPid value to detect a trace. If tracking is active, the malware still installs but doesn’t signal.
Sansek says an unexpected spike in Magento emails “Payment Transaction Failed Reminder” could mean an exploit and also recommends monitoring for “kworker” or “fc-cache” processes, suspicious cron entries, and temporary files.
If a compromise is suspected, it is recommended to rotate the Magento credentials.
At the time of writing, Adobe has not released fixes for StyleSmuggler, but the company’s next scheduled security release is tomorrow, September 8.
Until fixes are provided, Sansec recommends that website administrators disable GraphQL as a mitigation measure.
BleepingComputer has reached out to Adobe to ask if a fix for StyleSmuggler is planned for release tomorrow, but the company has yet to respond.
Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.
The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.
