Ransomware, Malware

Over half of Magento stores subjected to PolyShell intrusions

Shopping online. cardboard box with a shopping cart logo in a trolley on a laptop keyboard. Shopping service on The online web.

Intrusions harnessing the PolyShell exploit impacting Adobe Commerce and Magento Open Source instances have already compromised 56.7% of all vulnerable e-commerce stores since widespread exploitation commenced last week, reports BleepingComputer.

Malicious actors have already exploited PolyShell, which stems from Magento's REST API, to compromise a leading automaker's e-commerce website with a new payment card skimmer, which enables stealthier data exfiltration through the use of Web Real-Time Communication, according to a Sansec analysis.

After leveraging WebRTC to establish a connection with a hardcoded command-and-control server, the skimmer obtains the second-stage payload, whose execution is deferred via "requestIdleCallback" to evade robust Content Security Policy controls. Organizations using Adobe Commerce and Magento Open Source have been advised to examine Sansec's list of IP addresses that scan PolyShell-impacted web stores.

While PolyShell has already been addressed in version 2.4.9-beta1, Adobe has yet to provide a security update for production versions of Adobe Commerce and Magento Open Source.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds