By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Magento StyleSmuggler Zero-Day Exploited for Linux Backdoor
A critical zero-day vulnerability, identified as "StyleSmuggler," is actively being exploited to compromise websites running on Magento and Adobe Commerce platforms. This vulnerability affects all versions of these e-commerce platforms, posing a significant threat to online businesses. The exploitation of StyleSmuggler allows attackers to deploy a backdoor on affected Linux servers, granting them persistent access and control over the compromised systems. The backdoor, identified as "Pylons," is a sophisticated piece of malware designed to evade detection and maintain a covert presence on the server. Security researchers at Wordfence first observed these attacks in late May 2024, noting a surge in exploitation attempts targeting Magento and Adobe Commerce installations. The attackers are leveraging the StyleSmuggler vulnerability to execute arbitrary code on the server, which is then used to download and install the Pylons backdoor. This backdoor provides attackers with capabilities such as file manipulation, command execution, and the ability to establish further connections to the compromised server. The nature of the attacks suggests a targeted campaign, likely aimed at harvesting sensitive data or using the compromised servers for further malicious activities, such as hosting phishing sites or launching other cyberattacks. The Pylons backdoor is notable for its use of Python and its ability to communicate over encrypted channels, making it more difficult to track and analyze. The attackers are reportedly using a specific user agent string, "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36," in their exploit attempts, which can aid in identifying malicious traffic. The exploitation chain begins with the StyleSmuggler vulnerability, which allows for remote code execution. Once executed, the malicious code fetches the Pylons backdoor from a remote server. The Pylons backdoor is designed to be stealthy, often masquerading as a legitimate system process. Its functionalities include downloading additional payloads, executing arbitrary commands, and maintaining persistence across server reboots. The attackers are actively scanning for vulnerable Magento and Adobe Commerce instances, indicating a broad and ongoing threat. The discovery and analysis of this threat were conducted by Wordfence, a prominent cybersecurity firm specializing in WordPress and e-commerce security. Their research highlights the persistent threat posed by zero-day vulnerabilities in widely used web applications and the sophisticated methods employed by attackers to maintain access to compromised systems. The lack of a patch for this vulnerability means that all users of Magento and Adobe Commerce remain at risk until Adobe releases a security update. Organizations using these platforms are strongly advised to implement immediate mitigation strategies, such as enhancing server monitoring, restricting access to sensitive directories, and reviewing server logs for any suspicious activity. The exploitation of a zero-day vulnerability underscores the importance of proactive security measures and rapid response to emerging threats in the e-commerce landscape. The StyleSmuggler vulnerability itself is a critical flaw that bypasses existing security controls, making it a prime target for malicious actors seeking to gain unauthorized access to e-commerce platforms. The Pylons backdoor's design suggests a focus on long-term compromise and data exfiltration, posing a substantial risk to the integrity and confidentiality of business operations and customer data. The ongoing nature of these attacks necessitates vigilance from system administrators and security teams managing Magento and Adobe Commerce environments.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.