logoalt Hacker News

Obsidian plugin was abused to deploy a remote access trojan

15 pointsby cmbaileyyesterday at 10:02 PM4 commentsview on HN

Comments

zhivotayesterday at 11:14 PM

Even being social engineering, the design of the plugin system allowing this means the platform is completely unusable as a sharing tool. It's good to know but to me this is not "I need to remember to have these settings correct to use a shared Obsidian vault", this for is instead "never accept a shared Obsidian vault, demand a plaintext export".

slowmoveryesterday at 10:28 PM

> The victim is prompted to enable the "Installed community plugins" synchronization feature.

Obsidian has the proper protections in place to prevent this type of attack, and the victims are being convinced to ignore them. This is just a successful social engineering event. I hate to see Obsidian dragged down by this headline, since this attack is not exploiting a vulnerability in it or its plugin system.

show 2 replies
ValveFan6666yesterday at 11:15 PM

[dead]