StyleSmuggler Rust-based backdoor deployment on Magento and Adobe Commerce hosts
Malware Activity
Summary
Hide ▲
Show ▼
A Rust-based backdoor is being dropped on Magento and Adobe Commerce servers after StyleSmuggler exploitation, giving attackers remote command-and-control on Linux hosts. The payload hides as [kworker/u:8:0] or fc-cache, and newer versions copy themselves to ~/.cache/fontconfig/fc-cache. A cron job every 30 minutes adds persistence, while the malware can beacon to remote infrastructure and receive commands. The activity turns a zero-day exploit into durable post-compromise access, raising the risk of long-lived control and stealth on affected servers.
Related Happenings
Magento Open Source and Adobe Commerce StyleSmuggler zero-day actively exploited security flaw
Vulnerability
H score25
First: 05.09.2026 23:14
Last: 05.09.2026 23:14
Sources 1
How related:
A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.
About this happening:
StyleSmuggler is a zero-day affecting Magento and Adobe Commerce that is being actively exploited to deploy a Rust-based Linux backdoor. Sansec says the fi...
Magento Open Source and Adobe Commerce StyleSmuggler zero-day actively exploited security flaw
VulnerabilityHow related: A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.
About this happening: StyleSmuggler is a zero-day affecting Magento and Adobe Commerce that is being actively exploited to deploy a Rust-based Linux backdoor. Sansec says the fi...
PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign
Campaign
H score89
First: 15.06.2026 12:59
Last: 15.06.2026 12:59
Sources 1
About this happening:
A multi-plugin supply-chain campaign targeted Awesome Motive WordPress plugins OptinMonster, TrustPulse, and PushEngage, with malicious JavaScript delivered th...
PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign
CampaignAbout this happening: A multi-plugin supply-chain campaign targeted Awesome Motive WordPress plugins OptinMonster, TrustPulse, and PushEngage, with malicious JavaScript delivered th...
Latest development: 15.06.2026 20:37
Awesome Motive said a server in its environment was compromised after exploitation of a known UpdraftPlus WordPress plugin flaw, allowing attackers to steal the CDN API key for a marketing website and modify JavaScript distributed through the company’s CDN. The company remediated the marketing site, moved it to a new server, and rotated all credentials, including the CDN API key, while stating that its application servers, source code, and account-data systems were not breached.
Magento Open Source and Adobe Commerce PolyShell unauthenticated RCE flaw
Vulnerability
H score30
First: 19.03.2026 22:01
Last: 19.03.2026 22:01
Sources 1
About this happening:
PolyShell is a Magento Open Source and Adobe Commerce vulnerability that can enable unauthenticated code execution and account takeover across stable version...
Magento Open Source and Adobe Commerce PolyShell unauthenticated RCE flaw
VulnerabilityAbout this happening: PolyShell is a Magento Open Source and Adobe Commerce vulnerability that can enable unauthenticated code execution and account takeover across stable version...
Timeline
-
07.09.2026 19:50 2 articles · 2h ago
StyleSmuggler exploitation deploys a Rust-based Linux backdoor on Magento and Adobe Commerce hosts
Exploitation ObservedStyleSmuggler exploitation against Magento and Adobe Commerce hosts on September 4, 2026 deployed a small Rust-based Linux backdoor after PHP code injection through Magento’s template system triggered code execution on a target already running the latest security updates; the payload hides as [kworker/u:8:0] or fc-cache, can copy itself to ~/.cache/fontconfig/fc-cache, and installs a cron job every 30 minutes for persistence.
Show sources
- Magento StyleSmuggler zero-day exploited to deploy Linux backdoor — www.bleepingcomputer.com — 07.09.2026 19:50
- Magento StyleSmuggler zero-day exploited to deploy Linux backdoor — www.bleepingcomputer.com — 07.09.2026 19:50
-
07.09.2026 19:50 1 articles · 2h ago
Adobe has not released a StyleSmuggler fix
Mitigation Patch UpdateOn September 7, 2026, Adobe Enterprise Support said it was working on a fix for StyleSmuggler without giving a release timeline, while Adobe had not yet released fixes and its next scheduled security release was September 8; until patches are available, Sansec recommends disabling GraphQL, monitoring for unexpected Magento "Payment Transaction Failed Reminder" emails, suspicious "kworker" or "fc-cache" processes, cron entries, and temporary files, and rotating Magento credentials if compromise is suspected.
Show sources
- Magento StyleSmuggler zero-day exploited to deploy Linux backdoor — www.bleepingcomputer.com — 07.09.2026 19:50