Attackers are actively exploiting StyleSmuggler, an unpatched unauthenticated remote-code-execution chain in Magento Open Source that may also affect Adobe Commerce. The attack injects malicious PHP through Magento template style properties, poisoning a log or report file before triggering its execution through the Payment Transaction Failed Reminder email-rendering path. Sansec reproduced the chain on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9 systems, while a confirmed victim ran fully patched 2.4.6-p15.
Following execution, attackers install a persistent Linux implant using cron and masquerade processes as kworker. Reported indicators include download host 247.cdnflare.xyz, WebSocket-over-TLS C2 endpoint 99.84.67.186:443, and artifacts under ~/.local/share/.gvfsd/ and /tmp/.kw_*. No vendor CVE, patch, or formal workaround was available at the time of reporting; organizations should investigate Magento hosts for compromise, apply layered web controls, consider disabling GraphQL where feasible, and rotate session and application credentials on potentially affected deployments.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
Sansec observed a second Rust-based StyleSmuggler backdoor variant masquerading as fc-cache. The implant disguised command-and-control traffic as NTP replies and collected host and public-IP information before beaconing.
Sansec publicly reported that the actively exploited unauthenticated StyleSmuggler RCE affects Magento Open Source and Adobe Commerce, including current Magento releases through 2.4.9. Adobe had not issued a CVE, advisory, official patch, or workaround as of September 6.
Disrex Group responded to two compromised Magento stores and identified a third that had been attacked but not breached. Its investigation documented poisoned system.log files, evolving attacker headers, direct cron-file persistence, and additional malware hashes and attack-source indicators.
By 23:10, Sansec detected the StyleSmuggler implant on unrelated stores, indicating the activity was not limited to the first confirmed victim. The implant used cron persistence and masqueraded as a kworker process.
Sansec found the active campaign and reproduced the complete unauthenticated attack chain on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9 installations within hours. The research established that current Magento Open Source releases were exploitable despite existing safeguards.
Sansec recorded the first confirmed StyleSmuggler exploitation at 22:20 against a Magento 2.4.6-p15 store that had July and August 2026 security patches applied. The unauthenticated chain poisoned Magento-managed files and led to remote code execution and backdoor deployment.
Disrex documented that StyleSmuggler can drive Magento DI compiler scanner classes to include attacker-selected poisoned log or report files, executing injected PHP. It released and verified a source-level guard for Magento 2.4.6–2.4.9 that blocks those scanner sinks during HTTP requests while retaining CLI compilation functionality.
Sansec analyzed a 485-byte PHP dropper on affected stores that writes a header-protected web shell under the Magento product-image cache. It assessed this tooling as apparently unrelated to the StyleSmuggler implant and could not determine whether the separate actor gained access through StyleSmuggler or another route.
Disrex Group, ProxiBlue, and Graycore published unofficial hardening patches targeting affected Magento classes and email-template functions. Disrex cautioned that its rules block the observed attack pattern rather than remediate the underlying vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
9 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcecysecurity.news
Open sourcecysecurity.news
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcethehackernews.com
Open sourcesansec.io
Open sourcegithub.com
Open sourcesansec.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.