Cybersecurity — 2026-03-26

PolyShell Zero-Day Enables Mass E-Commerce Compromise; Novel WebRTC Skimmer Bypasses Content Security Policies

A critical vulnerability in Magento Open Source and Adobe Commerce called PolyShell allows unauthenticated attackers to upload polyglot executables via REST API cart-item file-upload endpoints, exploiting three missing security checks to achieve remote code execution. The flaw has existed since the first Magento 2 release, affecting an estimated 112,000–130,000 active storefronts. Under mass exploitation since March 19 with 50+ scanning IPs, PolyShell has hit 56.7% of all vulnerable stores. Attackers are deploying a novel payment card skimmer that establishes WebRTC peer connections over DTLS-encrypted UDP to a hardcoded C2 server, exfiltrating stolen data outside HTTP channels entirely. The skimmer bypasses Content Security Policy by stealing valid nonces from existing page scripts to inject its payload. Sansec, which discovered both the vulnerability and the skimmer, reports finding payment skimmers on five multi-billion-dollar companies in two months, including a top-3 US bank and a top-10 global supermarket chain. Adobe addressed the flaw in pre-release version 2.4.9-alpha3, but no isolated patch exists for current production versions.

Analysis
The WebRTC exfiltration technique bypasses Content Security Policy protections that have been the primary defense against JavaScript-based skimmers. With 56.7% of vulnerable stores compromised and no production patch available, the window of exposure will likely persist for weeks. The targeting of a major automaker's e-commerce site suggests high-value targets are being specifically selected. All core facts — the PolyShell vulnerability, WebRTC skimmer technique, exploitation statistics (56.7%, 50+ IPs), and claims about five compromised multi-billion-dollar companies — originate from Sansec's own research disclosures. Both Bleeping Computer and The Hacker News explicitly attribute their reporting to Sansec, with THN adding minor supplementary technical analysis from Searchlight Cyber's Assetnote team on the vulnerability internals. No independent source has confirmed the exploitation scale or the named victim categories. High confidence in the technical details given Sansec's established track record in e-commerce security, but the impact claims rest entirely on their telemetry.
3 sources
  1. WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites - The Hacker News
  2. PolyShell attacks target 56% of all vulnerable Magento stores - Bleeping Computer
  3. Novel WebRTC skimmer bypasses security controls at $100+ billion car maker - Sansec

View in full brief →

UNCLASSIFIED // OPEN SOURCE