Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
stylesmuggler-ioc-toolkit — StyleSmuggler (CVE-2026-75650) IOC toolkit for Magento Open Source and Adobe Commerce. Detect compromised stores, Rust implants, PHP web shells, persistence artifacts, and known indicators of compromise. | Kitploit
도구/GitHubGitHub/jithinkrishnanrs/stylesmuggler-ioc-toolkit
Defensive ToolsIndicator of Compromise (IOC) ManagementVulnerability ScannersConfiguration AuditingWeb SecurityMalware AnalysisDigital ForensicsThreat IntelligenceIntrusion Detection

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
Incident Response
GitHubjithinkrishnanrs/stylesmuggler-ioc-toolkit

stylesmuggler-ioc-toolkit

StyleSmuggler (CVE-2026-75650) IOC toolkit for Magento Open Source and Adobe Commerce. Detect compromised stores, Rust implants, PHP web shells, persistence artifacts, and known indicators of compromise.

저장소 보기
3111일 전아직 검토되지 않음
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

StyleSmuggler IOC Toolkit — CVE-2026-75650

Magento zero-day · Adobe Commerce zero-day · CVE-2026-75650 · APSB26-146 · VULN-39341 · unauthenticated RCE · Magento malware · Magento backdoor removal · Magento 2.4.9 vulnerability · Rust implant · GraphQL styles injection · PHP web shell

Community indicators-of-compromise, a compromise scanner, and mitigation/patching guidance for StyleSmuggler (CVE-2026-75650) — the unauthenticated Magento Open Source / Adobe Commerce RCE disclosed by Sansec on September 5, 2026, with in-the-wild exploitation confirmed from September 4, 2026. Adobe published an official fix, APSB26-146, on September 7, 2026. If you searched for "StyleSmuggler IOC", "CVE-2026-75650", "APSB26-146", "VULN-39341", "Magento fc-cache malware", "Magento chronyd backdoor", "gvfsd-user Magento", or "Magento GraphQL styles RCE", this is the repo you want.

This is a defensive toolkit only. It contains detection signatures, a compromise scanner, and hardening/blocking rules built from published, first-hand incident reports. It does not contain exploit code, a proof-of-concept trigger, or anything that generates the attack payload. If you are looking for that, you are in the wrong repo — go patch and hunt instead.

Status as of this writing (2026-09-16)

VulnerabilityStyleSmuggler (Sansec's name) — CVE-2026-75650
VendorAdobe (Magento Open Source, Adobe Commerce)
CVECVE-2026-75650, assigned 2026-09-07
Adobe bulletinAPSB26-146, published 2026-09-07 20:20 UTC, Priority 1 (highest)
Also requiredAPSB26-138 (Adobe's regular September 2026 Commerce update, isolated patch 249-2026-09-001-CE, released 2026-09-08). Adobe states VULN-39341 must be applied in addition to this, not instead of it.
CVSS10.0 (3.1 and 4.0) — Critical. Full 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWECWE-1336, Improper Neutralization of Special Elements Used in a Template Engine
CISA KEVAdded to CISA's Known Exploited Vulnerabilities catalog 2026-09-08. Federal civilian executive branch (FCEB) remediation deadline: 2026-09-11. CISA's entry also flags this as requiring forensic/IR triage, with known ransomware-campaign use listed as "Unknown." Not just a Magento-community problem — this is now a federally-tracked, actively-exploited RCE.
Official patchShipped. Hotfix VULN-39341. Coverage is not universal — see the table below.
Authentication requiredNone — unauthenticated
Public exploit codeNo official PoC from Adobe/Sansec, but corroborating coverage notes a public GitHub repo (created ~Sept 8) describing itself as a research lab reproduction of the full chain — "no public exploit code" is weaker than it sounds. See docs/VULNERABILITY.md.
Affected versionsReproduced by Sansec on clean Magento Open Source 2.4.7, 2.4.8, 2.4.9; first confirmed victim ran 2.4.6-p15 fully patched (on prior patches)
ExploitationActive since 2026-09-04 22:20 UTC; continued through patch release; at least three independent toolkits confirmed exploiting the same entry point as of 2026-09-14. One exploit-tracking network reports 500+ distinct source IPs since Sept 9. Third-party WAF telemetry (Imperva) reports observed targets skew retail (~39.5%), lifestyle (~19.5%), and healthcare (~17.9%) — snapshots of individual vendors' visibility, not a claim about the full population of vulnerable stores.
Known Rust-implant variants[kworker/u:8:0] (Sept 4) → fc-cache v2.1.4 (Sept 6) → chronyd v2.1.5 (Sept 7) — same operator, same agent ID, versions incrementing. The chronyd build has been observed self-relaunching with no cron entry and a PID-1 parent.
Second, unrelated attackerPHP web shell in pub/media/catalog/product/cache/, preceded by a DNS-exfiltrating recon probe — independent of the Rust implant, confirmed 2026-09-07
Third, distinct toolkitConfirmed 2026-09-14. A remote-file-include backdoor edited directly into the core framework file vendor/magento/framework/App/View.php, gated by a cookie (gl_google_advisor_824808) disguised as ad-tech tracking. Fetches and executes a remote payload on demand, then deletes the transient file — nothing sits on disk between requests except the one tampered line in a vendor file.
Detonation without the emailConfirmed 2026-09-14. A second chain reaches full code execution via POST /paypal/transparent/response/ (PHP source in the query string) without ever rendering the "failed payment" email — markers MGPROOF::/MGKWSIM::, direct command execution through a kwc parameter. Mitigations built around the email trigger alone do not cover this.
Known delivery vectorsGraphQL styles[] parameter; invalid store code logged to var/log/system.log; file uploaded via Magento's customer custom options; the unrelated second attacker's Store:-header injection; PHP source in the /paypal/transparent/response/ query string (email-independent)
ImpactRemote code execution → persistent Rust-based backdoor, independent PHP web shell, a stealthy framework-level RFI backdoor, Redis session harvesting, credential/secret exposure via app/etc/env.php

Adobe's official patch coverage — check this before assuming you're safe

ProductCovered by APSB26-146No official fix
Adobe Commerce (incl. B2B, Cloud)2.4.4 – 2.4.9below 2.4.4
Adobe Commerce B2B1.3.3 – 1.5.3below 1.3.3
Magento Open Source2.4.6 – 2.4.9 only2.4.5 and below

If you're on an older, unsupported version, Adobe is not shipping you a fix even though you're just as exploitable. See docs/PATCHING.md for your options — including a note for Mage-OS users, who have a dedicated emergency release (3.5.0) rather than Adobe's Commerce-specific hotfix package.

This information changes fast. Cross-check against the primary sources before acting: Sansec's advisory and Adobe's bulletin. See docs/TIMELINE.md for a running log and cite your sources when you update anything here.

What StyleSmuggler actually is

Magento's own GraphQL styles parameter and its dependency-injection based file scanning are abused as a file-based deferred-execution primitive. The originally documented chain has two stages, but — as of Sansec's September 14 update — it is not the only confirmed chain, and detonation does not always require what stage two originally described:

  1. Poison. Attacker-controlled data reaches a Magento-generated log or report file (var/log/system.log via an invalid store code that Magento logs verbatim, or var/report/<hash>), smuggled in through the GraphQL styles[] parameter, a mutated request header, or (for the second, unrelated attacker below) the Store: header.
  2. Detonate. The attacker triggers Magento's standard "Payment Transaction Failed Reminder" email. Rendering that email (Magento's getProcessedTemplate path) walks a code path that lets Magento's own DI/code scanner include() the poisoned file, running the attacker's PHP. You do not need to open the email — rendering it server-side is enough — and the chain can fire even when mail delivery itself fails.
도구 다운로드