Find notable cyber news and cases, enriched with sources, timelines, and signals.

StyleSmuggler Rust-based backdoor deployment on Magento and Adobe Commerce hosts

Malware Activity
First reported
Last updated
Happening score
H score 17
1 unique sources, 1 articles

Summary

Hide ▲

A Rust-based backdoor is being dropped on Magento and Adobe Commerce servers after StyleSmuggler exploitation, giving attackers remote command-and-control on Linux hosts. The payload hides as [kworker/u:8:0] or fc-cache, and newer versions copy themselves to ~/.cache/fontconfig/fc-cache. A cron job every 30 minutes adds persistence, while the malware can beacon to remote infrastructure and receive commands. The activity turns a zero-day exploit into durable post-compromise access, raising the risk of long-lived control and stealth on affected servers.

Related Happenings

Magento Open Source and Adobe Commerce StyleSmuggler zero-day actively exploited security flaw

Vulnerability
H score25 First: 05.09.2026 23:14 Last: 05.09.2026 23:14 Sources 1

How related: A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.

About this happening: StyleSmuggler is a zero-day affecting Magento and Adobe Commerce that is being actively exploited to deploy a Rust-based Linux backdoor. Sansec says the fi...

PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign

Campaign
H score89 First: 15.06.2026 12:59 Last: 15.06.2026 12:59 Sources 1

About this happening: A multi-plugin supply-chain campaign targeted Awesome Motive WordPress plugins OptinMonster, TrustPulse, and PushEngage, with malicious JavaScript delivered th...

Latest development: 15.06.2026 20:37

Awesome Motive said a server in its environment was compromised after exploitation of a known UpdraftPlus WordPress plugin flaw, allowing attackers to steal the CDN API key for a marketing website and modify JavaScript distributed through the company’s CDN. The company remediated the marketing site, moved it to a new server, and rotated all credentials, including the CDN API key, while stating that its application servers, source code, and account-data systems were not breached.

Magento Open Source and Adobe Commerce PolyShell unauthenticated RCE flaw

Vulnerability
H score30 First: 19.03.2026 22:01 Last: 19.03.2026 22:01 Sources 1

About this happening: PolyShell is a Magento Open Source and Adobe Commerce vulnerability that can enable unauthenticated code execution and account takeover across stable version...

Timeline

  1. 07.09.2026 19:50 2 articles · 2h ago

    StyleSmuggler exploitation deploys a Rust-based Linux backdoor on Magento and Adobe Commerce hosts

    Exploitation Observed

    StyleSmuggler exploitation against Magento and Adobe Commerce hosts on September 4, 2026 deployed a small Rust-based Linux backdoor after PHP code injection through Magento’s template system triggered code execution on a target already running the latest security updates; the payload hides as [kworker/u:8:0] or fc-cache, can copy itself to ~/.cache/fontconfig/fc-cache, and installs a cron job every 30 minutes for persistence.

    Show sources
  2. 07.09.2026 19:50 1 articles · 2h ago

    Adobe has not released a StyleSmuggler fix

    Mitigation Patch Update

    On September 7, 2026, Adobe Enterprise Support said it was working on a fix for StyleSmuggler without giving a release timeline, while Adobe had not yet released fixes and its next scheduled security release was September 8; until patches are available, Sansec recommends disabling GraphQL, monitoring for unexpected Magento "Payment Transaction Failed Reminder" emails, suspicious "kworker" or "fc-cache" processes, cron entries, and temporary files, and rotating Magento credentials if compromise is suspected.

    Show sources