StyleSmuggler zero-day backdoors Adobe Commerce stores

Attackers exploit a zero-day called StyleSmuggler in Adobe Commerce and Magento to inject PHP into templates and install Rust backdoors on stores running versions 2.4.7–2.4.9.

Threat actors have been exploiting a zero-day vulnerability in Adobe Commerce and Magento to inject PHP into storefront templates and install persistent backdoors, researchers report. Attacks have been observed against stores running Magento 2.4.7, 2.4.8 and 2.4.9 since September 4.

Security firm Sansec named the flaw StyleSmuggler. The vulnerability lets attackers hide PHP payloads inside the platform’s ‘styles’ properties. The exploit runs in two stages: attackers first inject PHP by creating a failure report, then trigger execution when Magento resends a ‘Payment Transaction Failed Reminder’ email or when email delivery fails. No customer interaction is required for the code to run.

Successful intrusions have written a backdoor to compromised systems. The implant is written in Rust and was observed connecting to a command-and-control server and awaiting orders. Early samples ran with a process name shown as “[kworker/u:8:0]”; a second variant that appeared on September 6 used “fc-cache”.

The backdoor hides control traffic using messages that resemble NTP server replies. Those messages include host telemetry such as an agent ID, hostname and username, memory and disk usage, OS version, uptime, whether root access is available, the implant version and the store’s public IP before regular beaconing begins.

Sansec reported finding the campaign on September 4 at 22:40 UTC and reproducing the exploit chain on clean installations within hours. The firm says the flaw affected deployments that had applied the July and August 2026 patches.

Adobe’s monthly Patch Tuesday release is scheduled for September 8; it is not clear when a fix specifically for StyleSmuggler will be issued.

Sansec recommends that operators monitor for unexpected spikes in payment-failure notifications, review recent template changes, audit outgoing emails and inspect running processes for unfamiliar names. The firm also suggests network checks for abnormal NTP responses and unusual outbound connections to unknown servers.

Articles by this author