Particle.news

Adobe Patches Active Magento Zero-Day Used to Install Rust Backdoors and PHP Web Shells

Adobe released an emergency hotfix to stop ongoing attacks that inject PHP into Magento templates and leave persistent, hard-to-detect implants.

Overview

  • Security researchers say exploitation began on September 4 and uses a template-system PHP injection, dubbed StyleSmuggler, that triggers code execution when Magento renders its ‘Payment Transaction Failed Reminder’ email.
  • Attackers have deployed a small Rust-based Linux backdoor that masquerades as benign processes such as kworker, fc-cache or chronyd and hides command traffic by sending 48-byte UDP packets to NTP port 123.
  • A second actor has been observed dropping a compact PHP installer that writes a stealthy web shell into the product-image cache that only responds when presented with a special header.
  • Adobe published hotfix VULN-39341 on September 8 and is urging immediate application plus rotation of encryption keys and all credentials, maintenance-mode remediation steps and full forensic compromise assessments.
  • Because many stores were vulnerable even when recently patched, administrators should hunt for signs of compromise—failed-payment email spikes, suspicious processes and cron jobs, unexpected PHP files under pub/media, and outbound NTP-like traffic—and treat suspected hosts as breached.