A zero-day vulnerability called StyleSmuggler, affecting all versions of Magento and Adobe Commerce, is used in attacks to deploy a backdoor. The first exploitation incident was reported on September 4 at a facility that had the latest security updates installed. E-commerce security company Sansec says Adobe Enterprise support confirmed earlier today that it is working on a fix, but did not provide a timeline for its release. Magento is Adobe’s popular open source e-commerce platform, installed on over 160,000 websites, including 14,000 of the top 1 million sites. Linux backdoor The exploit, discovered in the wild by Sansec, abuses the Magento templating system by injecting PHP code to create a fake failed payment email, which triggers code execution. When successfully exploited, a small Rust-based backdoor is installed as a background process, disguised as [kworker/u:8:0]. In newer versions, this process is disguised as fc-cache and copied to ~/.cache/fontconfig/fc-cache. According to Sansec researchers, the attacker also adds a cron job configured to repeat every 30 minutes to ensure resiliency. Although Sansec has not observed any subsequent activity, the malware can communicate with remote infrastructure and receive commands. The researchers note that earlier backdoor samples used TLS/WebSockets to communicate with a command and control (C2) address, while newer versions disguise their traffic as Network Time Protocol (NTP). They send UDP packets on port 123 and use hostnames reminiscent of time synchronization infrastructure, helping to mask malicious traffic as NTP and pass through firewalls. The malware also determines the server’s public IP address using services such as ipify, icanhazip, ident.me and ipinfo.io and checks the Linux TracerPid value to detect traces. If tracking is active, the malware is still installed but does not transmit a signal. Sansec says that a sudden spike in Magento emails reminding you that a payment transaction has failed could indicate exploitation, and also recommends monitoring “kworker” or “fc-cache” processes, suspicious cron entries and temporary files. If you suspect a hack, it is recommended to change your Magento credentials. At the time of writing, Adobe has not released a fix for StyleSmuggler, but the company’s next scheduled security release is scheduled for tomorrow, September 8th. Until fixes are available, Sansec recommends that website administrators disable GraphQL as a mitigation measure. BleepingComputer has reached out to Adobe to see if it plans to release a fix for StyleSmuggler tomorrow, but the company has not yet responded. General prevention scores may obscure what happens after initial access. Once attackers use valid credentials, prevention effectiveness drops dramatically. The Blue Report 2026 measures security technique by technique based on 338 million simulations run in customer production environments. Get report Post navigation 4 Reasons to Add Host Hotel Stocks to Your Portfolio Now APT Travel Group launches £1,000 weekly discount vouchers