Categories: Cybersecurity

A Magento Zero-Day Is Backdooring Online Stores Right Now, and There’s No Patch

Every so often a security flaw arrives with the worst possible combination of traits, and this is one of them. A zero-day vulnerability in Magento Open Source and Adobe Commerce, the software behind a large chunk of the world’s online stores, lets an attacker take over a store’s server without logging in, and it is being exploited in the wild as you read this. The Dutch e-commerce security firm Sansec, which found it and named it StyleSmuggler, took the unusual step of publishing before its analysis was even finished, with a blunt explanation: stores are being compromised right now.

The details are grim. The flaw affects every current version, including the latest 2.4.9, and needs no authentication, so any attacker with a network path to a store can attempt it. A successful hit gives them code execution on the server and quietly installs a persistent backdoor. As of this writing, Adobe has not issued a CVE, an advisory, or a fix, and its security bulletin still ends at an August update. The next scheduled Adobe security release may or may not even address it.

Patching would not have saved you

Here is the detail every store owner needs to hear, and it is unusual. Being up to date offered no protection. Sansec’s first observed victim was running the highest patch level Adobe ships for its release line, fully current, and it was breached anyway. Both of the stores that a hosting firm called Disrex investigated were hit inside the roughly eight-hour window between the first attacks and the moment any defence for the flaw existed. As Disrex put it, patch status was irrelevant here, which is the part merchants most need to hear. When there is no patch and attacks are already live, the only sane assumption is that you may already be a target.

The backdoor itself is built for stealth. It disguises its process under a name that mimics a legitimate Linux kernel thread, installs itself in a hidden folder in the user’s home directory rather than the obvious web root, and re-adds its restart schedule within a second of being deleted. On one store it made no outbound connection at all, quietly reading customer session data from the site’s own internal database, which makes it nearly invisible to defences that watch for suspicious network traffic.

What to do before Adobe acts

With no official fix, the immediate steps are damage control. Sansec’s interim advice is to temporarily disable GraphQL, the API layer the exploit abuses, unless your storefront specifically needs it. Independent researchers have published unofficial code patches and web-server rules, though they caution these blunt the current attack rather than close the hole entirely.

There is one low-tech warning sign worth flagging above all, because spotting it requires no tools at all. The exploit tends to trigger a burst of “Payment Transaction Failed” emails, and in at least one case the store emailed its own owner a broken-looking failed-order notice full of raw, unresolved template code. That garbled email, easy to dismiss as a glitch, was actually exhaust from the attack, and forwarding it is what led investigators to the implant within the hour.

A fair caveat: this is a fast-moving story built on early research, with Adobe silent and the full exploit still unpublished. But the exploitation is confirmed by more than one source, and the usual reassurance, just patch, does not apply. So if you run a Magento or Adobe Commerce store, what should you assume right now? That the door is open, and it is on you, not the vendor, to bar it until a real fix arrives.

Viktor Drake

This website uses cookies.