Mass exploitation of Magento and Adobe Commerce critical flaw: 3,800+ online shops hacked
A hacker calling itself Lockster hacked thousands of stores but forgot to lock its own server.

Online stores breached. Image by Cybernews / Shutterstock / StockLab.
- Lockster compromised more than 3,800 online stores through a critical Magento and Adobe Commerce flaw.
- The group exposed its own server, revealing stolen data from at least 3,834 websites.
- Its malware steals checkout details, payment keys, and other sensitive store data.
- Adobe released an emergency fix, but affected stores must also rotate credentials and remove hidden backdoors.
An aggressive mass-exploitation campaign has breached more than 3,800 online stores in the past few weeks alone. The attacker leveraged a critical flaw in Magento and Adobe Commerce to gain root access, installed credit card skimmers, and exfiltrated payment gateway keys and other data, leaving customers exposed to future attacks.
From local bookstores to major international brands – thousands of online shops are getting breached, exposing customers to financial and privacy dangers.
The victim list includes a major French kitchenware retailer, a German wholesaler of screws and fastening supplies, a European computer hardware retailer, a Nordic health, nutritional supplements, and wellness retailer, several car-brand merchandise stores, and automotive parts suppliers.
The Cybernews research team discovered the ongoing malicious campaign on September 14th, 2026. Thousands of online shops have already been compromised by a single threat actor since around September 4th.
The attacker calls itself Lockster, but has left part of its own infrastructure unlocked and open to anyone on the internet.
The exposed staging server contained data stolen from at least 3,834 identifiable websites – mostly online shops.
“Cumulatively, these websites have processed at least 2 million orders in 2026,” said Aras Nazarovas, a security researcher at Cybernews.
The exposed server hosts malicious code, Lockster’s tools and artifacts, some data dumps of exfiltrated data, including private keys for the Braintree payment gateway. The number of compromised credit cards is unknown because malware exfiltrates most of the records to other protected endpoints.
Lockster is just one of several hacking groups exploiting a recently disclosed critical zero-day vulnerability in Magento and Adobe Commerce. This bug was first identified and named “StyleSmuggler” by Sansec.
The discovered infrastructure and malicious tools overlap with indicators of compromise (IoCs) detailed in Sansec’s report on the zero-day exploitation.
Adobe addressed the StyleSmuggler vulnerability with an emergency hotfix and urged immediate upgrades and credential rotation.
Extensive user data harvested
The hacker implants compromised store websites with a credit card skimmer – malware that illegally captures credit or debit card and other information from unsuspecting users.
This skimmer is polymorphic, meaning that each hacked website has slightly altered malicious code to prevent detection by traditional antivirus solutions.
This malware targets every visitor’s checkout form and collects the data as follows:
- Card number (PAN), CVV / CVC, expiration month/year
- Payment method
- First name and last name
- Address (street, city, postal/ZIP code, region/state, country)
- Phone number
- Hostname of the store
- Browser User-Agent
- Timestamp
With root access, the attacker also decrypts and steals the merchant’s private keys for payment gateways such as Braintree and Authorize.net, which allow the merchant to accept credit card payments. Valid merchant IDs with private keys could lead to fraudulent charges and refunds, as well as access to additional payment records.
“Casual visitors have no indication that the website might have been compromised,” Nazarovas warns.
The hacker deploys a server-side sniffer to capture any other sensitive orders, keys, or data.
“Some artifacts pointed to custom post-exploitation steps for specific targets. These include DNS poisoning, password hash cracking, CCTV camera probing, and password spraying,” Nazarovas said.
Different data types were exfiltrated to several corresponding attacker-controlled servers.
The exposed data also revealed that Lockster attempted to demand ransoms. One of the artifacts is a ransom note sent to a casino, demanding $150,000.
What is Magento?
Adobe Commerce and Magento are essentially the same core e-commerce software.
Adobe acquired Magento in 2018 for $1.68 billion, and later rebranded the paid commercial versions to Adobe Commerce. It’s one of the major platforms alongside other giants like Shopify and WooCommerce, used by major brands and thousands of smaller shops.
Over 150,000 active online stores use Magento.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
How does Lockster break in?
The attacker used a target list of storefronts known to use Magento versions 2.4.2 to 2.4.9. Nothing on the server indicates how the list was compiled – the hacker might’ve used web scanning engines or custom crawlers.
To leverage the unauthenticated remote code execution (RCE) vulnerability and gain root access on Magento hosts, the attacker sends a single POST (HTTP) request to the unprotected /customer/address_file/upload endpoint.
It uploads a specially crafted (polyglot) GIF file that looks like a normal image but hides executable PHP code inside.
The file is hidden in the request’s specific data field, “custom_attributes[country_id],” and the system fails to properly validate the uploaded content.
The POST request also uses a clever formatting trick to inject specific commands, forcing the web server’s system files to read and execute the hidden code.
Lockster leveraged several other known vulnerabilities to escalate privileges when needed.
“The source code and artifacts indicate that Lockster operates the primary campaign responsible for the initial exploitation of the zero-day vulnerability,” Nazarovas said.
Sansec’s original report detailed extensive IoCs of the threat actor that operated a zero-day exploitation campaign. Matching infrastructure includes credit card exfiltration domains, NTP-disguised C2 infrastructure, and kworker/fc-cache backdoor implants.
The analyzed threat actor started certain post-exploitation tasks on September 6th, 2026, according to the timestamps found on the server.
Although the recovered data doesn’t reference any use of AI, Cybernews researchers assess that the campaign was heavily orchestrated by agentic AI systems. Several indicators point to AI-driven automation: tasks were coordinated and tracked among numbered bots, and malicious scripts were iterated many times to refine campaign functionality.
Obsessed with control: 3 backdoors and protection against competing hackers
On compromised websites, Lockster established at least 3 different persistence mechanisms:
- A hidden system implant, written in Rust: this covert background process is called “kworker” or “fc-cache” to resemble a routine system process. It maintains a covert, encrypted connection to the command-and-control (C2) server using NTP (Network Time Protocol) and WebSocket.
- Backdoor SSH access: the attacker sets up multiple system user accounts, protected by cryptographic secb_key (ed25519) keys and a single shared password. The hacker used these usernames: cfgmgr, monclean, pkgsync, opsmaint, apppush, bakctl, pkgpulse, cachehook, dbaide, pkgprobe, jobaide, tracguard.
- Additional Magento admin accounts: the attacker exfiltrated all admin credentials and added additional administrator profiles within the platform.
Moreover, Lockster seemed aware that other threat actors are exploiting the same vulnerability, so it also guarded the compromised server against common exploitation techniques.
Lockster disabled the 6 most commonly occurring administrator accounts, so no commonly targeted accounts would be present in default Magento installations. It was also constantly tracking which of the compromised websites got patched and took measures to maintain access or lock competitors out.
Assume compromise: cleanup is required to protect users
The exposed Lockster’s server highlights the importance of patching critically vulnerable systems immediately.
Applying the VULN-39341 (APSB26-146) emergency hotfix released by Adobe is no longer enough – treat the website as potentially compromised.
Cybernews researchers urge Magento and Adobe Commerce online shop owners to investigate their host servers for Indicators of compromise, as listed in Sansec’s report.
Administrators are advised to look for network calls to malicious domains (listed below), presence of kworker/fc-cache binaries, presence of sk.js(credit card skimmer) file under /magento_root/pub/media/<...> or magento_root/media/<...>.
Check two specific payment files in your Magento system:
- PaymentInformationManagement.php
- GuestPaymentInformationManagement.php
Search for malicious strings fsnif2, fsnif1fsnif2c, $fsn_a['x_host'] and $fsn_a['x_host'].
“If any indicators of compromise are found, remove the backdoor binaries, remove the skimmer, reset all secret keys accessible from the compromised host, audit host administrator users and Magento administrator users to remove the attacker’s access to your system,” Nazarovas said.
Cybernews has disclosed the details about the attacker’s server to the authorities.
Indicators of compromise
Domains:
- js-static[.]io
- checkout-cdn[.]com
- ntpsync[.]io
- ntp[.]reposync[.]to
- ntp[.]synctime[.]to
- ntp[.]syncstime[.]to
Exploited vulnerabilities for privilege escalation:
- CVE-2026-31431 "Copy Fail" (AF_ALG socket + splice + CMSG)
- PwnKit, CVE-2021-4034
- nf_tables LPE, CVE-2026-23111