ADVERTISEMENT

Mass exploitation of Magento and Adobe Commerce critical flaw: 3,800+ online shops hacked

A hacker calling itself Lockster hacked thousands of stores but forgot to lock its own server.

online stores breach

Online stores breached. Image by Cybernews / Shutterstock / StockLab.

Ernestas Naprys
Ernestas Naprys Senior Journalist
September 28, 2026 5 min read
Key takeaways:
attacker exposed directory
Exposed threat actor’s web directory. Image by Cybernews.
compromised stores sorted by order counts
The threat actor tracked compromised stores, orders, and supported payment methods. Image by Cybernews.

Extensive user data harvested

  • Card number (PAN), CVV / CVC, expiration month/year
  • Payment method
  • First name and last name
  • Address (street, city, postal/ZIP code, region/state, country)
  • Phone number
  • Email
  • Hostname of the store
  • Browser User-Agent
  • Timestamp
Exfiltrated braintree keys
Exfiltrated Braintree private keys. Image by Cybernews.
Ransom note image found on the attacker_s server
Ransom note found on the threat actor’s server. Image by Cybernews.

What is Magento?

ADVERTISEMENT

How does Lockster break in?

lockster mentions on the attacker_s server
The threat actor calls itself “Lockster.” Image by Cybernews.
Polymorphic skimmer builder
Polymorphic credit card skimmer malware builder. Image by Cybernews.

Obsessed with control: 3 backdoors and protection against competing hackers

  1. A hidden system implant, written in Rust: this covert background process is called “kworker” or “fc-cache” to resemble a routine system process. It maintains a covert, encrypted connection to the command-and-control (C2) server using NTP (Network Time Protocol) and WebSocket.
  2. Backdoor SSH access: the attacker sets up multiple system user accounts, protected by cryptographic secb_key (ed25519) keys and a single shared password. The hacker used these usernames: cfgmgr, monclean, pkgsync, opsmaint, apppush, bakctl, pkgpulse, cachehook, dbaide, pkgprobe, jobaide, tracguard.
  3. Additional Magento admin accounts: the attacker exfiltrated all admin credentials and added additional administrator profiles within the platform.
Adobe software company
Software company Adobe. Photo by Samuel Boivin/NurPhoto via Getty Images

Assume compromise: cleanup is required to protect users

  • PaymentInformationManagement.php
  • GuestPaymentInformationManagement.php

Indicators of compromise

  • js-static[.]io
  • checkout-cdn[.]com
  • ntpsync[.]io
  • ntp[.]reposync[.]to
  • ntp[.]synctime[.]to
  • ntp[.]syncstime[.]to
  • CVE-2026-31431 "Copy Fail" (AF_ALG socket + splice + CMSG)
  • PwnKit, CVE-2021-4034
  • nf_tables LPE, CVE-2026-23111
Ernestas Naprys
Senior Journalist
ADVERTISEMENT