Intrusions harnessing the PolyShell exploit impacting Adobe Commerce and Magento Open Source instances have already compromised 56.7% of all vulnerable e-commerce stores since widespread exploitation commenced last week, reports BleepingComputer.
Malicious actors have already exploited PolyShell, which stems from Magento's REST API, to compromise a leading automaker's e-commerce website with a new payment card skimmer, which enables stealthier data exfiltration through the use of Web Real-Time Communication, according to a Sansec analysis.
After leveraging WebRTC to establish a connection with a hardcoded command-and-control server, the skimmer obtains the second-stage payload, whose execution is deferred via "requestIdleCallback" to evade robust Content Security Policy controls. Organizations using Adobe Commerce and Magento Open Source have been advised to examine Sansec's list of IP addresses that scan PolyShell-impacted web stores.
While PolyShell has already been addressed in version 2.4.9-beta1, Adobe has yet to provide a security update for production versions of Adobe Commerce and Magento Open Source.
Malicious actors have already exploited PolyShell, which stems from Magento's REST API, to compromise a leading automaker's e-commerce website with a new payment card skimmer, which enables stealthier data exfiltration through the use of Web Real-Time Communication, according to a Sansec analysis.
After leveraging WebRTC to establish a connection with a hardcoded command-and-control server, the skimmer obtains the second-stage payload, whose execution is deferred via "requestIdleCallback" to evade robust Content Security Policy controls. Organizations using Adobe Commerce and Magento Open Source have been advised to examine Sansec's list of IP addresses that scan PolyShell-impacted web stores.
While PolyShell has already been addressed in version 2.4.9-beta1, Adobe has yet to provide a security update for production versions of Adobe Commerce and Magento Open Source.




