The threat actor tracked compromised stores, orders, and supported payment methods. Image by Cybernews
An Attacker Leaves His Own Door Open
An attacker hacked thousands of shops. Then he left the door to his own infrastructure open.
A check of an exposed server run by the Lockster operator showed the scale of the damage. Through a critical zero-day in Magento Open Source and Adobe Commerce, attackers compromised at least 3,834 sites. Most were online stores. The campaign began around September 4 and stayed active to the end of the month.
What the Open Server Revealed
The open infrastructure offered a rare chance. Researchers could gauge the real infection scale from the attacker’s own data, not from scanning.
The server held malicious tools, dumps of stolen data, and details about targets. Together, the discovered stores processed at least two million orders since the start of 2026. However, no one could establish how many payment cards were stolen.
About the StyleSmuggler Vulnerability
The attacks rely on StyleSmuggler, tracked as CVE-2026-75650. It carries the maximum score of 10.0 on CVSS 3.1. The flaw allows remote execution of arbitrary code. It needs no account and no user action.
On September 7, Adobe issued an emergency fix, VULN-39341. It covers the affected branches of Adobe Commerce, Magento Open Source, and Adobe Commerce B2B.
Sansec recorded the first attacks on September 4. At that time, no patch existed. The flaw injects PHP code into the template system. The server then runs that code while it builds the standard failed-payment email. Nobody needs to open the message. The code executes during email preparation.
Persistence After the Break-In
Lockster did not stop at first access. Hidden processes named kworker or fc-cache appeared on servers. Extra SSH accounts and new Magento administrators also appeared.
Several persistence mechanisms let the attacker survive cleanup attempts. As a result, he kept control even after the owner closed the original hole.
A Polymorphic Skimmer Steals Card Data
On checkout pages, the operator planted a polymorphic skimmer. Its code changed slightly from site to site. The malware captured the card number, the CVV or CVC, and the expiry date. It also took the payment method, name, address, phone, and email of each buyer.
The differences between copies were meant to defeat simple signature detection.
Stolen Gateway Keys
Server access also let the attacker steal private keys for payment gateways, including Braintree and Authorize.net. A server-side sniffer captured other secrets too. Such keys may give access to more payment data. Moreover, criminals could use them for fraudulent charges or refunds.
Lockster sent some records to closed nodes. Therefore, 3,834 sites remain only a confirmed minimum.
Tracking Patches and Rivals
Lockster watched which infected stores had installed the patch. He then tried to keep access to updated systems. He also disabled common administrator account names, which hindered rival attackers. Among the materials, researchers found a ransom note. It demanded $150,000 from one compromised business.
Why Patching Alone Is Not Enough
For stores already breached, a fix alone falls short. After installing VULN-39341, Adobe recommends rotating the encryption key. Owners should also rotate every secret it protects. That list includes administrator passwords, integration tokens, and payment API keys. It also covers database credentials, SSH keys, and secrets of third-party extensions.
A Campaign Still Under Way
As of September 28, the investigation described the campaign as ongoing. The flaw stopped being a zero-day once the fix arrived on September 7. Still, attackers exploited it before the patch. Installed backdoors also survive the update.
Consequently, the figure of 3,834 shows confirmed compromises, not the final scale of the attack.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.