We will be speaking at Meet Magento Germany on 22 October 2026. Come say hello.

Proudly supporting Mage-OS contributors — limited lifetime free access. Mage-OS contributors, please reach out. Terms, policies, and FAQ are still being finalized.

Cybersecurity

I Tracked Down The Hacker Behind a Magento PolyShell Attack. Here's What They Told Me.

8 minutes read
Laurentius Judhianto
Laurentius JudhiantoFounder, Platform Engineer
I Tracked Down The Hacker Behind a Magento PolyShell Attack. Here's What They Told Me.

Let's Talk Hacking... Did I ever hack a site, yea a few. It's out of curiosity. I had to learned it out of necessity, to think like a hacker, to test out our defense against the dark arts. Thus I began my journey by interviewing one of the creator of Magento PolyShell and this is what they told me.

A conversation I probably should not have had. But did anyway — and what came out of it should be required reading for anyone running Magento.

It started with a name inside the code

I was reverse-engineering a PolyShell variant — reading through the files it drops, tracing the logic, mapping what it was actually trying to do. Standard forensic work.

Then I hit a variable name that stopped me. Then a credit — hackers embed their calling card in the tools they write, a "Coded by" or a greets line with their handle, their crew, sometimes their country. Then a function name written in a way that isn’t how English speakers write things.

The patterns were unmistakably Indonesian — a specific cadence, a specific shorthand that you only recognise if you know it.

I’m Indonesian. I know it.

Hacker Credits - Indonesian
Indonesian hacker credits found inside the PolyShell source
One of PolyShell Attacker
The breadcrumbs led here — one of the PolyShell attacker profiles

That changed things. This wasn’t an anonymous blob of obfuscated script. There was a person on the other side, and they had left traces of themselves in the code. I kept reading. The breadcrumbs pointed to a site. The site pointed to Telegram.

I sent a message — blunt, in Indonesian:

Laurentius: Bisa bahasa Indonesia? Mau ngobrol sebentar? (Can you speak Indonesian? Want to chat for a bit?)
Hacker: Reluctant at first. Then: yes.

This post is a summary of a real conversation, reviewed and verified by one of the threat actors behind PolyShell. How we communicate beyond the initial Telegram contact is anonymous and will not be disclosed. The information shared here is intended strictly for educational purposes — to help Magento merchants and developers understand how these attacks work and how to defend against them.

A word before the interview

During the conversation, they described themselves as curious — in it for the rank, not the money. They said they draw a line at the destructive stuff. We’re giving them the benefit of the doubt on that, and publishing accordingly.

But here’s what we also know: anyone can say they’re the curious kind. The tools, the CVE lists, the automated bots — they’re the same whether someone is chasing a leaderboard or dropping a skimmer on your checkout. Intent doesn’t change the exposure. So read this for the technique, not the character reference.

With that said — here is what they had to say.

The conversation

Laurentius: So you’re hacking Magento — what’s the reason?
Hacker: Just curiosity. And chasing ranks.
Laurentius: How do you pick your targets?
Hacker: Spray and pray. I was experimenting with automated bots — most targets are just caught by chance.
Laurentius: Are you experienced with Magento? How did you find the vulnerability?
Hacker: No. I’m not a developer, let alone a Magento one. I can’t code — AI helped me. But hacking isn’t like coding. I just stumbled on a CVE post about Magento 2 and decided to build an API attack. It works like this every time. A new CVE is a new toy to play with.
Laurentius: Really? You’ve never actually used Magento 2?
Hacker: No. I have a Magento 2 installation inside a cPanel just to test payloads against — but I’ve never actually used it as a store. I don’t even know how to operate it. If you’re on NGINX, that blocks a full RCE. If you have Magento 2 on Apache — and worse, with cPanel — it’s almost certainly gone.

No Magento knowledge. No coding skills. A public CVE post and an AI assistant. That is the full development stack for the attack.

There are leaderboards for this. Whole communities built around who breaches the most notable targets. Zone-H — a public defacement archive that has been running since the early 2000s — is where findings get posted as proof, like a trophy wall. If your domain appears there, it is public record.

No list. No research into who you are. A range of IPs, a payload, and whatever responds. Tools like Shodan — a search engine for internet-connected devices — make this even easier: search for a specific software signature and it hands you a list of every exposed instance on the public internet. The spray doesn’t even need to be blind.

Your web server is a security control. NGINX with a tight config blocks full remote code execution on the exact payload that walks straight through Apache + cPanel. This is not a minor configuration preference — it is the difference between a nuisance and a total site compromise.

Who’s on the list — and yes, Google is there

Laurentius: What high-profile sites got implicated?
Hacker: A lot. Heineken, Samsung, Google. In the Netherlands, a few agencies. Even Magento.com.
Laurentius: Any sites hosted on Hypernode?
Hacker: Check their C2 server and see if any went through. Nope — Hypernode is secured.
Laurentius: What are they actually trying to get out of this?
Hacker: Nothing. I’m just curious — this is for rank. However other hackers in my community think differently. They use it to create ransomware, skimming, replacing the checkout module’s API with theirs. I disagree with those practices. But hackers be hackers.
Zone-H Polyshell List - Breach
Zone-H breach list — PolyShell findings posted as public record
Google Merch Polyshell
Google Merch store listed among PolyShell breaches
Google Merch Website is in Magento
Google's merch store — running on Magento

Right. Hypernode ships with Sansec baked in — the best-known first-alert name in Magento security.

That last category is the one that should keep Magento merchants up at night. A ransomware attack announces itself. A checkout-API swap does the opposite — it leaves your store running perfectly, orders processing normally, while quietly routing every card number through a third-party server. You might not know for weeks. Your customers won’t know at all.

Whether the person that finds you is the curious kind or the destructive kind — the entry point is the same. The only thing that changes is what happens after they get in.

Apache + cPanel + Magento: how bad is it?

Laurentius: Let’s go back to Apache and cPanel. How dangerous is it really?
Hacker: The answer was screenshots.
Apache Vulnerabilities
Apache vulnerability evidence shared during the conversation
Apache Webshell Injection
Webshell successfully injected on an Apache-hosted Magento site

One agency site, fully compromised. Then more. Not hypotheticals — active findings with evidence. The combination of Apache, cPanel, and an unpatched Magento CVE is not a worst-case scenario for them. It is a routine outcome.

On WAFs: some good, most just expensive regex

Laurentius: What do you think of WAFs?
Hacker: Some good, some just cash-grab enterprise regex. Look — you can bypass free Cloudflare just by faking the UA when curling. There’s a published list of bypasses for every WAF out there, as long as you can sniff the fingerprint first. For me, Imperva is a good one.
Laurentius: But Cloudflare proxy hides your origin IP, right?
Hacker: Oh hahaha — this is where people misunderstand. Hiding it doesn’t mean it’s not there. Sites like crt.sh and reverse DNS show the history of your SSL certificates. With enough effort that trail points back to you. It’s just buying time. Once we know the IP, we attack the IP directly.

The free tier of most WAFs is signature matching. It gets bypassed by anyone who has looked up the bypass list — which is public, maintained, and circulated in exactly the communities this person runs in. Awesome-WAF on GitHub is one such list: a comprehensive, community-maintained collection of WAF fingerprints and bypass techniques for virtually every major vendor.

crt.sh is a public certificate transparency log — every SSL certificate ever issued for your domain is listed there, including historical ones pointing to your old origin IPs before you moved behind a proxy. Combined with reverse DNS lookups, it can walk an attacker straight back to your server.

Lock your origin firewall to your CDN’s IP ranges only. And don’t underestimate what crt.sh and old DNS records reveal — they are a historical map to your real address.

How the attacks actually happen

Laurentius: Walk me through it — how does hacking work in practice?
Hacker: Most hacks are API-based. You don’t see it, but it’s there. Unauthenticated open APIs. Unsanitized input. IDOR — access one record, use the same token to exfiltrate the rest. Some sites fail to secure their files with .htaccess or nginx config. These are sensitive files, and the developer didn’t know it. Getting hacked or not — the thin layer between them is those config files. And please: no open ports if you can avoid it.
Laurentius: And Google dorking on top of that?
Hacker: This is how you go from one known breach to wrecking havoc at scale. You take a known exposure from a breached site, build a dork query, and Google hands you every other site with the same vulnerability. One foothold becomes a thousand targets.
Laurentius: So what’s a high-profile recent target?
Hacker: Google uses Magento for their merch store. We emailed them. They didn’t seem to care. But we’ve already marked their site as breached.
Using Google to Dork - Mapping Out Attacks
Google dorking — one known breach pattern maps to thousands of vulnerable sites
Google Merch Breached with Polyshell (No RCE)
Proof-of-concept file dropped on Google’s merch store server

IDOR in plain terms: if I can access /api/order/1001, I try /api/order/1002. If the server hands it over without checking whether I’m allowed to see it, I can walk the entire order history. Not a sophisticated attack — just trying the obvious thing. Tools like ffuf automate this at scale — fuzzing thousands of endpoint patterns in seconds to find the ones that shouldn’t exist.

The “no open ports” point pairs with nmap — the standard tool for port scanning. Before launching an API attack, a reconnaissance pass with nmap maps every open port on a server. Every unnecessary open port is a door that was already found before you even knew someone was looking.

Whether Google’s security team received it, triaged it, filed it, or it went into a blackhole — we don’t know. The claim is documented, the finding was reportedly sent, and the response was silence.

The agency story — and why the original target doesn’t matter

Laurentius: Any cybersecurity tips?
Hacker: I’m a hacker — I don’t secure sites, so I don’t know much. Here’s one or two things. No Apache, avoid it entirely or really know what you’re doing. No cPanel — you’re asking for problems. Same with WordPress.
Laurentius: If you had one message for the Magento community?
Hacker: I honestly don’t understand how such a fatal bug could affect millions of websites, even though I’ve only tested fewer than 200,000 of them. I’m sure Magento won’t make a mistake this serious again. Good luck, Magento. To all developers and site owners: we’re just having some fun. It took me and my two friends 8 hours to upload all these files. See how many sites are affected. Stop using Apache or LiteSpeed and switch to OpenResty or Nginx. Bypassing LiteSpeed is literally a game for kids just starting to learn how to hack; it’s honestly too easy. Do yourselves a favor and move on. Indonesia, 2026 — L4663R666H05T, Simsimi, and BROKENPIPE (came from Italy)
Example of Burpsuite Runs
Burpsuite demonstrating the agency breach

One agency WordPress site breached. We know their cPanel. We got their entire client list — and all those clients are compromised too. The original target didn’t even matter.

The agency was the skeleton key. Every client they managed, every site behind them — all of it from one WordPress install. And combine that with Google dorking from a single known breach. This alone will wreck havoc big time.

How I ended the call

I told them the truth:

Laurentius: We are StoreFrame — a small company in the Netherlands. Please don’t attack us, we share the same roots 😉. If I find something in the future, I will let you know first so you can fix it. But we will not stop these engagements. This is who we are.
Hacker: Would you like me to teach you how to hack? I lead some hacking forums, helping newbies. So you want to be my student?

Yeah. We can start tomorrow.

We didn’t continue. The StoreFrame team decided to learn on our own terms instead — Vibehacking. COK: Claude on Kali.

What to actually do with this

The scary part of this story isn’t a genius adversary. It’s the opposite. An automated bot, built with AI by someone who openly can’t code, pointed at a fresh public CVE, sprayed at the entire internet. You don’t get targeted. You get found.

“We’re too small to be a target” is not a defense. Being small just means you’re in the spray radius alongside Heineken, Samsung, and Google’s merch store. The spray doesn’t care about your revenue.

The actual defense is boring and it works: no Apache + cPanel, close your ports, protect your sensitive files, lock your origin to your CDN, patch CVEs fast, and keep an eye on Zone-H for your own domain.

And remember — whether the hacker that finds you is the curious kind or the destructive kind, you won’t know in advance. Build as if it’s the latter.

If you’re running Magento on Apache with cPanel and haven’t patched recent CVEs — this is your warning. It is not a matter of if. The spray is always running.

What this actually means for your Magento store

Run NGINX. This is not a brand preference — it is a structural advantage. Apache is not inherently insecure, but a correctly hardened Apache config is genuinely rare. Most Apache installs in the wild carry default settings that well-known payloads walk straight through. NGINX with a tight config eliminates entire classes of attack before a single line of PHP ever runs.

If you are running Magento on cPanel + Apache, that is not just a configuration risk — it is a shared blast radius. cPanel hosts multiple sites under the same environment. Compromise one, and everything else in that cPanel is exposed. Attackers know this. They target cPanel specifically because a single entry point pays off across every site on the account.

Sansec and Hypernode are genuinely among the best in the business — both for Magento hosting and eCommerce security. That is not a referral. It is what the attacker said, unprompted, when asked directly. When someone actively trying to breach Magento stores tells you a platform is secured, that endorsement carries more weight than any marketing page.

The dominant attack vector is API-based — and AI is making it cheaper by the day. Attackers are no longer writing exploits from scratch. They are prompting AI to do it. The gap between a CVE disclosure and a working automated exploit is now measured in hours, not weeks.

A Magento CVE with a high CVSS score is not just a patch notice — it is a starting gun. The higher the score, the more attractive the target. Hackers triage CVE lists the same way security teams do, and they move faster. Expect a working exploit within hours of a critical disclosure. Expect it to be automated and sprayed at scale within days. Once a store is breached, a webshell is persistent by design — it survives cache flushes, deployments, even server reboots. Getting rid of it cleanly is genuinely hard. Patching fast is not optional hygiene. It is the only window you have.

StoreFrame is a management platform built for Magento merchants — infrastructure, security, and operations in one place. NGINX by default, no cPanel, automated patching. Built specifically so that the spray lands on nothing.

See how StoreFrame secures Magento infrastructure
Laurentius Judhianto
Laurentius JudhiantoFounder, Platform Engineer

A founder, an engineer at heart, an independent consultant who seek alternatives to the mainstream — Currently focused in burning AI tokens to deliver the best agentic e-Commerce experience.

View More
Self-Hosted Proof of Work with ALTCHA: A Turnstile Alternative for Magento Feature Image
8 min read
LJ
Laurentius JudhiantoFounder, Platform Engineer

One decision saved us setup time on every store, kept catalogue pages fast and stopped more bots: a self-hosted, Turnstile-style challenge that installs itself.

How to Build a Bot Score: 11 Signals That Separate Scrapers from Shoppers Feature Image
6 min read
LJ
Laurentius JudhiantoFounder, Platform Engineer

More than ten detectors score every request before anything is decided. Here is the scoreboard, what each signal is bad at, and the customers we annoyed on the way.

How to Spot a Fake Chrome: JA4 and HTTP/2 Fingerprinting Explained Feature Image
5 min read
LJ
Laurentius JudhiantoFounder, Platform Engineer

Every bot says it is Chrome. The handshake says otherwise. How we read JA4 and HTTP/2 fingerprints at the edge, why we needed both, and where they fail.

OpenResty vs NGINX, Caddy and Traefik: Choosing The Edge For Magento Feature Image
8 min read
LJ
Laurentius JudhiantoFounder, Platform Engineer

There are a dozen ways to put a web server in front of Magento. I tried most of them and landed on OpenResty — NGINX with Lua superpowers. Here's the honest case for it, and against the alternatives.

Magento Anti-Bot and Anti-Scraping: A Layered Defence Guide for Self-Hosted Stores Feature Image
11 min read
LJ
Laurentius JudhiantoFounder, Platform Engineer

Half of a Magento store's traffic are bots, and today's scrapers solve puzzles and rent home internet. Here is the layered strategy we run, with real numbers.

Three Magento Zero-Days in One Year. Here's What I Learned and How They're "Similar". Feature Image
11 min read
LJ
Laurentius JudhiantoFounder, Platform Engineer

SessionReaper, PolyShell and StyleSmuggler hit different parts of Magento months apart, from different people. Side by side they stop being three stories and start looking like one reused recipe.

The Perfect Agentic “Playground” for Magento Operators.

Bring your own cloud key and Claude subscription. We ship the containerized Magento platform — you keep the keys, the data, and the control.

StoreFrame management hub Console view with a Claude Code session answering questions about a Magento store