2026-04-17 04:53 UTC
Threat actors abuse #Obsidian its legitimate community plugin ecosystem, specifically the #ShellCommands and #Hider plugins, to silently execute code when a victim opens a shared cloud vault targeting #Windows and #macOS.
It does require manually enabled sync of community plugins.
https://thehackernews.com/2026/04/obsidian-plugin-abuse-delivers.html
Replies (1)
-
@schmidt_fu@mstdn.social 2026-04-17 05:20
@secupriv Interesting, I had a conversation just yesterday about how to sensibly scan the plugins in an #Obsidian vault. Even the official ones come without a package.json (which could be tampered anyway). Are we back to scanning every file on opening, or is there something more efficient for plain javascript snippets?