Unpatched Magento flaw exploited to plant stealthy Linux backdoor

A zero-day vulnerability named StyleSmuggler in Magento and Adobe Commerce is being actively exploited, with the first incident recorded on September 4 against a fully patched system. Attackers inject PHP code through the template system to trigger a fake payment-failure email, which installs a Rust-based backdoor disguised as a system process. The malware communicates via NTP-like traffic and sets up a cron job for persistence; Adobe has not yet released a fix, though a scheduled security update is expected soon.
The backdoor employs sophisticated evasion, masking its command-and-control traffic as standard Network Time Protocol packets to slip past firewalls. It also checks for tracing tools and will silently install without beaconing if detected, while using public IP services to identify its host. Administrators should watch for a sudden spike in payment failure reminders, as well as unusual kworker or fc-cache processes.
Given Magento powers over 160,000 online stores, the zero-day's success against a fully patched system is alarming. Until Adobe's scheduled security update arrives, disabling GraphQL is the recommended interim defense. Rotating credentials is advised for any suspected compromise, as the malware establishes persistence through a half-hourly cron job.
The exploitation of StyleSmuggler could severely impact e-commerce operators and their customers, as a fully patched system remains vulnerable. Merchants may face data theft, site defacement, or financial fraud if the backdoor is used for further intrusions. Consumers shopping on affected platforms could see their payment details compromised. The stealthy nature of the malware may delay detection, allowing prolonged unauthorized access. Until a patch is deployed, the reliance on temporary mitigations leaves many online businesses exposed to significant operational and reputational risks.