Skip to main content
← Back to Demos
Malware intermediate · 15 min

StyleSmuggler: Unpatched Magento Zero-Day Backdoor Implants Flagged by Metascan (2026-09-06 CISO Daily Digest)

The 2026-09-06 CISO Daily Digest reported that Dutch e-commerce security firm Sansec published a September 5 advisory for StyleSmuggler, an unauthenticated vulnerability in Magento Open Source and Adobe Commerce that lets attackers run code on a store's server and install a persistent backdoor — with exploitation already underway since September 4 ('Sansec is publishing early because stores are being compromised right now'). As of September 6 Adobe had published no advisory, CVE identifier, patch, or workaround; Sansec says all current versions are affected, including 2.4.9, and the first observed victim ran 2.4.6-p15 with Adobe's July and August 2026 updates applied — patch status did not matter. Hosting firm Disrex Group, which responded to two compromised stores, confirmed a Sansec Shield customer (Store A, Magento 2.4.8) was breached at 23:10 UTC on September 4 with Shield active, hours before Sansec's first blocking rules existed. The implant runs as a background process disguised under the legitimate kernel-thread name [kworker/u:8:0], installs a ~1.9 MB stripped static Rust binary (x86-64 and arm64) at ~/.local/share/.gvfsd/gvfsd-user, and re-arms itself every five minutes through a cron entry written directly to the spool file — on one store the line appeared 1,728 times; on another the implant made no outbound connections at all but held 28 connections to the local Redis instance, reading Magento's session storage. For defenders, the hard truth of this episode is that a fully patched, actively protected store was breached anyway — and every implant still had to arrive and execute somewhere. This demo reproduces the file-boundary half of that defense safely: the package ships EICAR test files standing in for the implant-shaped binary and its staged payloads — a classic eicar.com, an eicar.txt, a compiled Windows PE embedding the EICAR string, and a ZIP-wrapped EICAR — alongside a clean control file (no real malware, nothing destructive). MetaDefender Metascan runs 30+ anti-malware engines (including ClamAV) over every variant in a single pass and flags them all, showing how a backdoored binary is stopped at the gateway, before it ever lands and executes on a store server or endpoint (MITRE ATT&CK T1190 Exploit Public-Facing Application).

Attack Technique

Unauthenticated remote code execution on public-facing e-commerce servers (Magento Open Source / Adobe Commerce 'StyleSmuggler' zero-day, exploitation since 2026-09-04 per Sansec) planting a persistent server-side backdoor implant disguised as a kernel thread; payloads crossing the file boundary as EICAR stand-ins, flagged by multiscanning before execution (T1190)

MITRE ATT&CK

T1190 ↗

Platforms

linux

File Types

.com.exe.txt.zip

MetaDefender Capabilities

Metascan

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---