Overview
- Security researchers say exploitation began on September 4 and uses a template-system PHP injection, dubbed StyleSmuggler, that triggers code execution when Magento renders its ‘Payment Transaction Failed Reminder’ email.
- Attackers have deployed a small Rust-based Linux backdoor that masquerades as benign processes such as kworker, fc-cache or chronyd and hides command traffic by sending 48-byte UDP packets to NTP port 123.
- A second actor has been observed dropping a compact PHP installer that writes a stealthy web shell into the product-image cache that only responds when presented with a special header.
- Adobe published hotfix VULN-39341 on September 8 and is urging immediate application plus rotation of encryption keys and all credentials, maintenance-mode remediation steps and full forensic compromise assessments.
- Because many stores were vulnerable even when recently patched, administrators should hunt for signs of compromise—failed-payment email spikes, suspicious processes and cron jobs, unexpected PHP files under pub/media, and outbound NTP-like traffic—and treat suspected hosts as breached.