started · updated
Magento and Adobe Commerce hit by StyleSmuggler zero-day exploit
A critical zero-day vulnerability, dubbed ‘StyleSmuggler’, is being actively exploited in Magento Open Source and Adobe Commerce platforms. Security firm Sansec reported that the campaign began around September 4, 2024, targeting e-commerce stores through an unauthenticated remote code execution (RCE) flaw.
The attack chain leverages the GraphQL interface to inject malicious PHP code into system files, such as logs or failure reports. The payload is then triggered during the rendering of ‘Payment Transaction Failed Reminder’ emails. Notably, the malicious code executes while the email is being generated, meaning a recipient does not need to open the message for the attack to succeed.
Once the initial breach occurs, attackers deploy a persistent backdoor written in Rust. This malware is designed to mimic legitimate Linux kernel processes to evade detection. The vulnerability affects multiple versions, including Magento Open Source 2.4.7, 2.4.8, and 2.4.9. Evidence suggests that even systems with recent security patches, such as version 2.4.6-p15, have been compromised. Experts recommend that merchants consider disabling GraphQL as a temporary mitigation until an official patch is widely deployed.
Entities
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 3 SOURCES] Attacks using the StyleSmuggler exploit were first observed around September 4, 2024. www.etailment.de · www.it-boltwise.de · thecyberexpress.com
- [● 2 SOURCES] The zero-day vulnerability is named StyleSmuggler. www.etailment.de · thecyberexpress.com
- [● 4 SOURCES] The exploit uses the GraphQL interface to inject PHP code. www.etailment.de · www.it-boltwise.de · sempreupdate.com.br · thecyberexpress.com
- [● 3 SOURCES] The vulnerability allows unauthenticated remote code execution (RCE). www.it-boltwise.de · sempreupdate.com.br · thecyberexpress.com
- [● 2 SOURCES] The attack triggers code execution during the rendering of failed payment reminder emails. www.etailment.de · thecyberexpress.com
- [○ 1 SOURCE] A store running version 2.4.6-p15 was compromised despite having all available patches applied. thecyberexpress.com
- [● 3 SOURCES] Attackers install a persistent backdoor using a Rust-based application. www.etailment.de · sempreupdate.com.br · thecyberexpress.com
- [● 2 SOURCES] Vulnerable versions include Magento Open Source 2.4.7, 2.4.8, and 2.4.9. www.etailment.de · thecyberexpress.com