Switch language한국어
Back to the list

Obsidian plugin was abused to deploy a remote access trojan | Hacker News

TL;DR AI

Key summary

2 min read
  1. A malicious Obsidian community plugin was used to deliver a remote access trojan.

  2. The Hacker News discussion split over whether this was social engineering or a product security failure.

  3. Critics pointed to Obsidian’s broad plugin permissions and lack of sandboxing as the real risk.

  4. The incident highlights how trusted third-party extensions can become a malware delivery path.

Read the original