Cybernews reports that the Lockster group exploited a critical Magento/Adobe Commerce vulnerability, breaching more than 3,800 e‑commerce sites and stealing payment data.
A coordinated cyber‑crime operation dubbed Lockster has weaponized a critical flaw in Magento and Adobe Commerce, compromising over 3,800 online stores and exfiltrating payment card information.
Vulnerability details and exploitation method
The flaw resides in the stylesmuggler component, which allows unauthenticated attackers to inject malicious CSS that executes arbitrary code on the server. By chaining this with default admin credentials, the group gained full administrative access to vulnerable e‑commerce platforms.
Lockster’s toolkit automates the discovery of sites running outdated Magento/Adobe Commerce versions, then deploys a payload that harvests credit‑card numbers, billing addresses, and other sensitive checkout data.
Scope of the attack
Security researchers estimate that the campaign has affected more than 3,800 distinct domains across multiple industries, including fashion, electronics, and home goods. Victims report fraudulent transactions and chargebacks amounting to millions of dollars.
- Over 3,800 compromised sites identified
- Payment data from thousands of customers stolen
- Persistent backdoors left for future exploitation
Mitigation and response
Adobe has released an emergency patch that addresses the stylesmuggler issue. Administrators are urged to apply the update immediately, rotate all admin passwords, and audit logs for suspicious activity.
Security firms recommend enabling multi‑factor authentication, restricting admin access by IP, and regularly scanning for outdated Magento modules to prevent similar breaches.
The scale of this campaign underscores the importance of timely patch management for e‑commerce platforms.
For a detailed analysis of the Lockster operation and remediation steps, see the original coverage by Cybernews.
Cybernews report on Magento/Adobe Commerce mass hacking campaign
Comments
No comments yet.