Safety researchers have found an actively exploited, unauthenticated distant code execution vulnerability affecting installations of Magento Open Supply and Adobe Commerce.
This vulnerability, often known as StyleSmuggler, permits attackers to inject PHP payloads into Magento’s template system and execute them by way of commonplace software workflows.
Sansec’s Forensics Crew reported that assaults started on September 4, focusing on internet-facing e-commerce shops. The group efficiently replicated the whole assault chain on clear variations of Magento Open Supply, particularly 2.4.7, 2.4.8, and a couple of.4.9.
Notably, one compromised sufferer was utilizing Magento 2.4.6-p15, which had safety patches from July and August 2026 put in and a clear patch-status report, suggesting that the presently accessible patches don’t tackle this vulnerability.
How StyleSmuggler Works
StyleSmuggler exploits fashion properties to avoid current safeguards in Magento’s template-handling performance. The assault follows a two-stage course of:
- The attacker injects, or “poisons,” PHP code into content material generated by Magento, probably by way of a mechanism for producing failure stories.
- Later, Magento renders the poisoned content material and executes the injected code when a failed fee notification electronic mail is processed.
The malicious PHP code executes throughout electronic mail rendering, so directors don’t have to open the ensuing “Cost Transaction Failed Reminder” message for the compromise to happen.
The assault can nonetheless succeed even when electronic mail supply fails, so the absence of suspicious emails shouldn’t be taken as proof {that a} retailer is unaffected.
Researchers noticed that attackers deployed a compact Rust-based background implant after gaining code execution. Earlier samples disguised themselves because the Linux course of [kworker/u:8:0], whereas newer variations, launched on September 6, use `fc-cache` to mix in with authentic system exercise.
The `fc-cache` variant copies itself to `~/.cache/fontconfig/fc-cache` and establishes persistence by way of cron jobs, restarting twice an hour. It writes its course of ID to a brief lock file named `/tmp/.fc_<8hex>.lock`.
The implant disguises command-and-control (C2) site visitors to look as Community Time Protocol (NTP) exercise. Each 60 seconds, it resolves the area `ntp.timesync.to` and sends 48-byte UDP packets over port 123.
Though these packets mimic NTP server replies, most of their contents are chunked MessagePack information that features the system’s hostname, username, working system model, reminiscence and disk utilization, uptime, root standing, implant model, and public IP tackle.
Earlier than initiating communication with its C2 server, the malware queries public IP discovery providers corresponding to `api4.ipify.org`, `ipv4.icanhazip.com`, `ipv4.ident.me`, and `ipinfo.io`.
It makes use of a truncated Consumer-Agent string that doesn’t match a authentic browser’s. Moreover, the malware checks the `TracerPid` worth in `/proc/self/standing`; if debugging is detected, it installs itself however doesn’t talk with its operators.
Retailers ought to instantly limit entry to Magento GraphQL if they aren’t utilizing a devoted mitigation product. Sansec recommends deploying its Defend safety, scanning hosts with eComscan, and rotating Magento credentials if any suspicious persistence or processes are recognized.
Directors ought to examine any sudden surges in failed fee reminder emails, suspicious cron entries, template-report artifacts containing `x_trace_`, and processes named `[kworker/u:8:0]` or `fc-cache`.
Indicators of Compromise
| Kind | Indicator |
|---|---|
| Malware obtain host | 247.cdnflare.xyz |
| Malware obtain host | 209.141.43.95/information/ |
| C2 server | 99.84.67.186:443 |
| Distant shell | windwsecurity.run:443 |
| NTP-shaped C2 | ntp.timesysnc.web:123 |
| NTP-shaped C2 | time.microsft.run:123 |
| NTP-shaped C2 | pool.microsft.studio:123 |
| New-build C2 | ntp.timesync.to:123 |
| Fallback C2 | ntp.synctime.to:123 |
| Fallback C2 | ntp.syncstime.to:123 |
| Attacker supply | 88.216.72.181 |
| SHA-256 | e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 |
| SHA-256 | b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420 |
| SHA-256 | 4352cabaa451e5a894535fbcc4d46628701303322a13745cb5479d7d0534ae8e |
| SHA-256 | d2fbf9eb75c495bfea48790d3b228fab0c15a282419c3d3f5e49294c4e1a3e82 |
| File path | ~/.cache/fontconfig/fc-cache |
| File path | ~/.native/share/.gvfsd/gvfsd-user |
| Course of | [kworker/u:8:0], fc-cache |
| Malicious request | POST /graphql?types[....]= |
| Malicious request | POST /paypal/clear/response/?=eval(base64_decode('.... |
Be aware: IP addresses and domains are deliberately defanged (e.g., [.]) to forestall unintended decision or hyperlinking. Re-fang solely inside managed risk intelligence platforms corresponding to MISP, VirusTotal, or your SIEM.
Preserve your SOC updated on energetic malware & phishing inside 24h of their emergence. Attempt ANYRUN to forestall incidents with early detection.








