StyleSmuggler Zero-Day Lets Attackers Backdoor Magento Stores
The flaw injects PHP into Magento’s template 'styles' property and triggers execution when the platform renders failed-payment emails.
Overview
- Sansec first observed active exploitation that deploys the chain on September 4 and researchers reproduced the end-to-end attack on clean installations within hours.
- The two-stage attack injects PHP into Magento’s template system via the 'styles' property and causes the code to run when Magento renders or resends a 'Payment Transaction Failed Reminder' email.
- The vulnerability affects current Magento releases including 2.4.7 through 2.4.9 and has been used against stores that had July and August 2026 patches applied.
- Successful compromises install a small Rust backdoor that hides as common Linux processes such as kworker, fc-cache or chronyd and speaks to command servers using NTP-like UDP packets to port 123 to evade simple detection.
- Sansec has published IOCs, malware hashes and hunting guidance while Adobe says it is working on a fix; administrators should assume compromise if indicators appear, perform full forensics, rotate credentials, consider disabling GraphQL as a temporary mitigation and hunt for hidden PHP web shells in pub/media.