Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce, attackers are able to run malicious code on an online store’s server without the need to log in. This flaw, named StyleSmuggler by Dutch e-commerce security company Sansec, has been actively exploited since September 4.

As of September 6, Adobe has not released any advisory, patch, or workaround for this vulnerability. Sansec has confirmed that all current versions of Magento are affected, including 2.4.9. The company was able to reproduce the full unauthenticated chain on clean Magento Open Source installations of versions 2.4.7, 2.4.8, and 2.4.9.

The first victim of this exploit was running Magento Open Source 2.4.6-p15 with the latest security updates applied, yet the store still fell victim to the attack. Sansec has not disclosed the number of stores compromised by this vulnerability.

While Sansec has not published a reproduction of the exploit chain on Adobe Commerce, Disrex Group, a Magento hosting and development company, has provided details on how two compromised stores were handled. The company recommends disabling GraphQL until Adobe releases a fix for the vulnerability.

Sansec has recommended using its eComscan scanner to detect the implant, with version 1.9.7 being able to terminate the process for Shield customers. Disrex has also published unofficial mitigations and server settings to protect against this exploit.

Hosting providers Nexcess and Liquid Web have implemented precautionary measures in response to this vulnerability. The origins of the attackers behind this exploit remain unknown.

The full exploit chain details have not been disclosed yet, but both Sansec and Disrex have provided indicators to help detect and mitigate the threat.

For stores already infected, Disrex has provided a cleanup guide that includes preserving evidence, removing the cron entry, flushing session storage, and rotating credentials.