Back to Intelligence

StyleSmuggler Zero-Day (CVE-2025-54236): Unauthenticated RCE Against Magento & Adobe Commerce — OTX Pulse Analysis & Detection Pack

SA
Security Arsenal Team
October 5, 2026
13 min read

AlienVault OTX pulse data confirms active, in-the-wild exploitation of StyleSmuggler (CVE-2025-54236) — an unpatched zero-day affecting all current versions of Magento Open Source and Adobe Commerce, including 2.4.9. Exploitation began on September 4th, 2026, and the vulnerability remains without an official patch at time of analysis, making every internet-facing Magento/Adobe Commerce storefront a live target.

The attack operates as a two-stage, fully unauthenticated remote code execution chain:

  1. Stage 1 — Injection: The adversary abuses the GraphQL API to inject malicious PHP code through the styles properties of CMS/email template content. This pathway deliberately evades Magento's built-in template security safeguards, which do not sanitize style attributes for executable content.
  2. Stage 2 — Execution: The injected payload is triggered when the platform renders a failed payment email template. Because payment failure notifications are a routine, high-frequency event on any live storefront, attackers can reliably detonate their payload simply by submitting a deliberately failing transaction — no authentication, no admin access, no user interaction required.

The objective aligns with classic Magecart-style monetization: persistent PHP backdoors on payment-processing infrastructure enable checkout skimming, payment card harvesting, customer PII theft, and secondary access resale to initial access brokers. Given that Adobe Commerce powers a significant share of global mid-market and enterprise e-commerce, the blast radius is severe. The inclusion of ecomscan.com in the indicator set — a domain spoofing a legitimate e-commerce security scanner — suggests attackers are also conducting defensive-evasion and impersonation operations against store administrators attempting to validate their security posture.

Assessment: HIGH confidence this campaign is financially motivated, operated by an e-commerce-focused criminal group with deep Magento internals knowledge. Expect rapid indicator rotation and secondary payload staging while the vulnerability remains unpatched.

Threat Actor / Malware Profile

Adversary attribution: Unknown. The tradecraft — GraphQL abuse, template-engine weaponization, and payment-flow triggering — mirrors historical Magecart cluster behavior (groups consistently monetizing payment card data from compromised checkout flows), but no formal attribution exists at this time.

Distribution method: Direct exploitation of internet-facing Magento/Adobe Commerce instances via unauthenticated GraphQL requests. No phishing, no supply-chain intermediary — this is pure external attack surface exploitation, meaning any exposed storefront is reachable in a single request.

Payload behavior: Stage-1 injection writes attacker-controlled PHP into template/style content stored in the application database or compiled template cache. On render of the failed-payment email, the PHP executes in the web server context (typically www-data, nginx, or apache user), giving the attacker:

  • Arbitrary command execution under the web server service account
  • Read access to app/etc/env.php — exposing database credentials, encryption keys, and admin session secrets
  • Ability to write persistent webshells into the webroot (pub/, var/, media/ directories)
  • Access to live checkout data and stored customer records

C2 communication: Observed infrastructure includes windwsecurity.run (typosquatted 'Windows Security' theme, consistent with staging/exfil) and ntp.timesysnc.net (typosquatted time-sync hostname — classic covert-channel masquerading where beaconing is disguised as NTP traffic). Outbound callbacks originate from the compromised web server itself, blending with legitimate storefront egress.

Persistence mechanism: Database-resident template content survives cache flushes and partial file-system cleanups — wiping webshells from disk does NOT remove the injection if the poisoned style/template record remains in the cms_block, email_template, or related tables. Expect attackers to also drop standalone PHP webshells under pub/media/ and var/ for redundant access.

Anti-analysis techniques: Style-property smuggling specifically bypasses Magento's template sandboxing; execution is deferred to a legitimate application event (payment failure email) rather than a direct attacker request, breaking naive request-to-payload correlation in WAF logs. The ecomscan.com indicator indicates active impersonation of security tooling to misdirect administrators during incident response.

IOC Analysis

The pulse delivers 15 indicators across four operationally distinct types:

TypeIndicatorsOperationalization
CVECVE-2025-54236Asset inventory cross-reference — identify ALL Magento/Adobe Commerce instances in your estate, including staging and forgotten microsites
Domainsecomscan.com, windwsecurity.runDNS sinkhole/block at resolver; proxy egress block; retro-hunt DNS query logs 90 days back
Hostnamentp.timesysnc.netBlock; alert on any host resolving it — legitimate NTP clients never query this; resolution itself is a compromise signal
File hashes (MD5/SHA1/SHA256)a07bc08eded18cc7317216cbbd7032d2, 11d6a0c1000576915584c49c7039206bbb4c24d1, b79dfdc1...1420, e315687a...26a7Deploy to EDR blocklists; sweep webroots and var//media/ directories on all storefront servers

SOC operationalization guidance:

  • Hashes are your highest-fidelity indicators for the dropped webshell payloads — push them to EDR custom indicators and VirusTotal Enterprise retrohunts immediately.
  • Domains/hostnames are disposable and will rotate; treat them as short-TTL network signals but mine passive DNS for historical resolutions to scope compromise windows.
  • The CVE is your strategic indicator — until Adobe ships a patch, detection engineering (below) is your only compensating control.
  • Hash reputation lookups via OTX DirectConnect API, MISP sync, or otx_v2 Python SDK; decode/stage indicators into your TIP and enforce bidirectional SIEM/EDR sync.

Detection Engineering

The following detections target the specific StyleSmuggler behaviors: web-server-spawned shell execution, GraphQL style-property injection, malicious template modification, and C2 masquerading as NTP.

YAML
---
title: Magento/Adobe Commerce Web Server Spawning Shell - StyleSmuggler Exploitation
id: 7f3a1c2e-9d4b-4e1a-a5f6-stylesmuggler01
status: experimental
description: Detects web server worker processes (php-fpm, apache, nginx) spawning shell interpreters or command execution utilities — consistent with StyleSmuggler CVE-2025-54236 post-exploitation where injected PHP executes system commands via the failed payment email render path.
author: Security Arsenal Threat Intelligence
references:
    - https://sansec.io/research/stylesmuggler
date: 2026/10/06
logsource:
    category: process_creation
    product: linux
    service: auditd
detection:
    selection_parent:
        ParentImage|endswith:
            - '/php-fpm'
            - '/php'
            - '/apache2'
            - '/httpd'
            - '/nginx'
    selection_image:
        Image|endswith:
            - '/bash'
            - '/sh'
            - '/dash'
            - '/curl'
            - '/wget'
            - '/nc'
            - '/ncat'
            - '/python'
            - '/python3'
            - '/perl'
            - '/base64'
    condition: selection_parent and selection_image
falsepositives:
    - Legitimate Magento cron jobs invoking CLI PHP scripts (cron.php, bin/magento) — filter on known cron parent chains
    - Deployment pipelines executing composer or setup:upgrade
level: high
tags:
    - attack.execution
    - attack.t1059
    - attack.t1190
---
title: StyleSmuggler GraphQL Style Property Injection Attempt
id: 8a4b2d3f-1e5c-4f2b-b6a7-stylesmuggler02
status: experimental
description: Detects inbound GraphQL or POST requests containing style attribute values carrying PHP code tokens (eval, base64_decode, system, shell_exec, assert) — the Stage 1 injection vector of CVE-2025-54236 targeting Magento/Adobe Commerce CMS and email template styles properties.
author: Security Arsenal Threat Intelligence
references:
    - https://sansec.io/research/stylesmuggler
date: 2026/10/06
logsource:
    category: webserver
    product: apache
    service: accesslog
detection:
    selection_method:
        cs-method:
            - 'POST'
            - 'PUT'
    selection_uri:
        cs-uri-stem|contains:
            - '/graphql'
            - '/rest/V1'
            - '/admin/cms'
            - 'email_template'
    selection_payload:
        cs-uri-query|contains:
            - 'eval('
            - 'base64_decode'
            - 'shell_exec'
            - 'system('
            - 'passthru'
            - 'assert('
            - 'preg_replace'
    condition: selection_method and selection_uri and selection_payload
falsepositives:
    - Rare; legitimate template content does not contain raw PHP function calls in style properties
level: critical
tags:
    - attack.initial-access
    - attack.t1190
    - attack.t1059.004
---
title: StyleSmuggler C2 Infrastructure Communication - NTP Masquerade
id: 9c5d3e4a-2f6d-4a3c-c7b8-stylesmuggler03
status: experimental
description: Detects outbound DNS resolution or network connection to known StyleSmuggler C2 and staging infrastructure, including the NTP-masquerading hostname ntp.timesysnc.net and typosquatted security tooling domains.
author: Security Arsenal Threat Intelligence
references:
    - https://sansec.io/research/stylesmuggler
date: 2026/10/06
logsource:
    category: dns
detection:
    selection:
        query|contains:
            - 'windwsecurity.run'
            - 'ntp.timesysnc.net'
            - 'ecomscan.com'
    condition: selection
falsepositives:
    - ecomscan.com may be queried by administrators researching the Sansec ecomscan tool — investigate context, treat web-server-origin queries as malicious
level: critical
tags:
    - attack.command-and-control
    - attack.t1071
    - attack.t1036
KQL — Microsoft Sentinel / Defender
// StyleSmuggler (CVE-2025-54236) Hunt — C2 communication, web-shell process chains, and PHP file writes
// Run against Microsoft Sentinel / Defender XDR — 14 day lookback
let C2Indicators = dynamic(["windwsecurity.run", "ntp.timesysnc.net", "ecomscan.com"]);
let WebShellHashes = dynamic([
    "a07bc08eded18cc7317216cbbd7032d2",
    "11d6a0c1000576915584c49c7039206bbb4c24d1",
    "b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420",
    "e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7"
]);
// 1) Network connections / DNS to StyleSmuggler C2
let NetworkHits = DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemoteUrl has_any (C2Indicators) or RemoteIP in (C2Indicators)
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort
| extend HitType = "C2 Network Communication";
// 2) Web server spawning shells (post-exploitation execution)
let ProcessHits = DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName has_any ("php", "php-fpm", "apache", "httpd", "nginx", "www-data")
| where FileName in~ ("bash", "sh", "dash", "cmd.exe", "powershell.exe", "curl", "wget", "nc", "ncat", "python", "perl")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine, AccountName
| extend HitType = "Web Server Shell Spawn";
// 3) Webshell file drops matching OTX hashes
let FileHits = DeviceFileEvents
| where TimeGenerated > ago(14d)
| where MD5 in (WebShellHashes) or SHA1 in (WebShellHashes) or SHA256 in (WebShellHashes)
| project TimeGenerated, DeviceName, FolderPath, FileName, SHA256, InitiatingProcessFileName
| extend HitType = "Known Webshell Hash";
// 4) Suspicious PHP writes into Magento webroot/media/var directories
let FileWriteHits = DeviceFileEvents
| where TimeGenerated > ago(14d)
| where ActionType == "FileCreated"
| where FolderPath has_any ("/pub/media/", "/var/", "/pub/static/", "/generated/")
| where FileName endswith ".php"
| where InitiatingProcessFileName has_any ("php", "php-fpm", "apache", "httpd", "nginx")
| project TimeGenerated, DeviceName, FolderPath, FileName, InitiatingProcessFileName, InitiatingProcessCommandLine
| extend HitType = "PHP Dropper in Web-Accessible Path";
union NetworkHits, ProcessHits, FileHits, FileWriteHits
| sort by TimeGenerated desc
Bash / Shell
#!/bin/bash
# ============================================================================
# StyleSmuggler (CVE-2025-54236) — Magento/Adobe Commerce IOC Hunt Script
# Run on suspect storefront servers. Read-only. Requires bash + standard GNU utils.
# ============================================================================
set -u

echo "=============================================="
echo " StyleSmuggler IOC Sweep — $(date -u '+%Y-%m-%d %H:%M:%S UTC')"
echo " Host: $(hostname)"
echo "=============================================="

# --- 1. Known webshell file hashes from OTX pulse --------------------------
MD5_IOC="a07bc08eded18cc7317216cbbd7032d2"
SHA1_IOC="11d6a0c1000576915584c49c7039206bbb4c24d1"
SHA256_IOCS="b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420 e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7"

WEBROOTS="/var/www /srv/www /usr/share/nginx /home/*/public_html /opt/magento"

echo ""
echo "[1] Scanning webroots for known webshell hashes..."
for root in $WEBROOTS; do
    [ -d "$root" ] || continue
    find "$root" -type f -name "*.php" -size -500k 2>/dev/null | while read -r f; do
        f_md5=$(md5sum "$f" 2>/dev/null | awk '{print $1}')
        f_sha256=$(sha256sum "$f" 2>/dev/null | awk '{print $1}')
        if [ "$f_md5" = "$MD5_IOC" ]; then echo "  [HIT-MD5] $f"; fi
        for h in $SHA256_IOCS; do
            if [ "$f_sha256" = "$h" ]; then echo "  [HIT-SHA256] $f"; fi
        done
    done
done

# --- 2. PHP files in web-accessible dirs modified in last 45 days ----------
echo ""
echo "[2] Recently modified PHP files in web-accessible paths (exploitation window: since 2026-09-04)..."
for root in $WEBROOTS; do
    [ -d "$root" ] || continue
    find "$root" \( -path "*/pub/media/*" -o -path "*/var/*" -o -path "*/pub/static/*" -o -path "*/generated/*" \) \
        -type f -name "*.php" -mtime -45 2>/dev/null | while read -r f; do
        echo "  [REVIEW] $f  ($(stat -c '%y' "$f" 2>/dev/null | cut -d. -f1))"
    done
done

# --- 3. PHP code injection tokens in style/template content on disk --------
echo ""
echo "[3] Grepping for StyleSmuggler injection tokens (eval/base64_decode in style contexts)..."
for root in $WEBROOTS; do
    [ -d "$root" ] || continue
    grep -rIl --include="*.php" --include="*.phtml" --include="*.html" \
        -E "(eval\(|base64_decode\(|shell_exec\(|passthru\(|assert\()" "$root" 2>/dev/null | head -50 | while read -r f; do
        echo "  [TOKEN] $f"
    done
done

# --- 4. Database check for poisoned template records (persistence) ---------
echo ""
echo "[4] Checking Magento env.php for DB credentials & querying template tables..."
for root in $WEBROOTS; do
    ENV_FILE=$(find "$root" -maxdepth 4 -path "*/app/etc/env.php" 2>/dev/null | head -1)
    if [ -n "$ENV_FILE" ]; then
        DB_HOST=$(grep -oP "'host'\s*=>\s*'\K[^']+" "$ENV_FILE" | head -1)
        DB_NAME=$(grep -oP "'dbname'\s*=>\s*'\K[^']+" "$ENV_FILE" | head -1)
        DB_USER=$(grep -oP "'username'\s*=>\s*'\K[^']+" "$ENV_FILE" | head -1)
        DB_PASS=$(grep -oP "'password'\s*=>\s*'\K[^']+" "$ENV_FILE" | head -1)
        if command -v mysql >/dev/null 2>&1 && [ -n "$DB_NAME" ]; then
            echo "  [DB] Querying email_template and cms_block for PHP tokens..."
            mysql -h "$DB_HOST" -u "$DB_USER" -p"$DB_PASS" "$DB_NAME" -e \
                "SELECT template_id, template_code, added_at, modified_at FROM email_template WHERE template_text LIKE '%eval(%' OR template_text LIKE '%base64_decode%' OR template_styles LIKE '%<?php%' OR template_styles LIKE '%eval(%';" 2>/dev/null
            mysql -h "$DB_HOST" -u "$DB_USER" -p"$DB_PASS" "$DB_NAME" -e \
                "SELECT block_id, identifier, creation_time, update_time FROM cms_block WHERE content LIKE '%<?php%' OR content LIKE '%eval(%' OR content LIKE '%base64_decode%';" 2>/dev/null
        fi
    fi
done

# --- 5. Network connections & DNS cache for C2 -----------------------------
echo ""
echo "[5] Checking active connections and logs for C2 indicators..."
(ss -tunp 2>/dev/null || netstat -tunp 2>/dev/null) | grep -Ei "windwsecurity|timesysnc|ecomscan" && echo "  [HIT] Active C2 connection!" || echo "  [OK] No active C2 connections in socket table."

echo ""
echo "[6] Grepping web server logs for C2 hostnames & GraphQL injection attempts..."
for logdir in /var/log/nginx /var/log/apache2 /var/log/httpd; do
    [ -d "$logdir" ] || continue
    grep -Ei "windwsecurity\.run|ntp\.timesysnc\.net|ecomscan\.com" "$logdir"/*.log 2>/dev/null | tail -20
    grep -Ei "POST.*graphql.*(eval|base64_decode|shell_exec)" "$logdir"/*.log 2>/dev/null | tail -20 | while read -r line; do
        echo "  [INJECT-ATTEMPT] $line"
    done
done

echo ""
echo "=============================================="
echo " Sweep complete. Escalate any [HIT]/[INJECT-ATTEMPT]/[TOKEN] findings."
echo "=============================================="

Response Priorities

Immediate (0–4 hours)

  • Block all network IOCs (windwsecurity.run, ntp.timesysnc.net, ecomscan.com) at DNS resolver, proxy, and egress firewall. Sinkhole internally to flush out already-compromised hosts.
  • Push file hashes to EDR custom indicator lists and sweep all storefront webroots, var/, pub/media/, and generated/ directories.
  • Run the bash hunt script on every Magento/Adobe Commerce server, including staging environments. Pay special attention to the database template-table queries — file-system cleanup alone does not remove this persistence.
  • Deploy the Sigma and KQL detections to SIEM/EDR and retro-hunt 30+ days (exploitation began September 4th, 2026).
  • If patching is unavailable (0-day), place WAF virtual-patching rules in front of /graphql and admin template endpoints blocking PHP function tokens in request bodies.

24 Hours

  • This is payment infrastructure — treat credential exposure as assumed. If compromise is confirmed, rotate: Magento admin credentials, database passwords in app/etc/env.php, encryption keys, payment gateway API keys (Stripe/Braintree/Adyen), and any CDN/WAF tokens stored in the application.
  • Verify payment channel integrity: review payment processor dashboards for unauthorized payout account changes, inspect checkout pages for injected JavaScript skimmers, and determine whether cardholder data was accessed — this may trigger PCI DSS breach notification obligations.
  • Force logout of all active Magento admin sessions; audit admin user creation events since September 4th.
  • Review email template and CMS block audit logs (or DB modified_at timestamps) for unauthorized template changes.

1 Week

  • Architecture hardening: Move Magento admin panels behind VPN/IP allowlists; restrict GraphQL schema exposure to only required storefront queries; deploy runtime application self-protection (RASP) or PHP hardening (disable_functions for eval, exec, shell_exec, passthru, system in the web SAPI while preserving CLI cron functionality).
  • Egress controls: Web servers handling checkout should have tightly scoped egress allowlists — a storefront has no legitimate reason to resolve arbitrary external domains like ntp.timesysnc.net. Default-deny egress breaks this C2 model entirely.
  • File integrity monitoring on webroots and database triggers/audit logging on email_template and cms_block tables.
  • Subscribe to Adobe PSIRT and Sansec advisories for the official CVE-2025-54236 patch; stage and test it in pre-production immediately upon release.
  • Conduct a lessons-learned review of external attack surface management — unpatched, internet-facing payment platforms should be continuously inventoried and prioritized in vulnerability management SLAs.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.