frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Obsidian plugin was abused to deploy a remote access trojan

https://cyber.netsecops.io/articles/obsidian-plugin-abused-in-campaign-to-deploy-phantom-pulse-rat/
38•cmbailey•2h ago

Comments

slowmover•1h ago
> The victim is prompted to enable the "Installed community plugins" synchronization feature.

Obsidian has the proper protections in place to prevent this type of attack, and the victims are being convinced to ignore them. This is just a successful social engineering event. I hate to see Obsidian dragged down by this headline, since this attack is not exploiting a vulnerability in it or its plugin system.

cmbailey•1h ago
Right, I'm a heavy Obsidian user myself, and love it.

I think the value of this disclosure is more in spreading awareness about plugins, and demonstrating the vector. Where less sophisticated users may think, "Oh, this is just a collection of markdown files. I don't need to be too worried about malicious code."

Groxx•1h ago
Ehm. No? https://obsidian.md/help/plugin-security#Plugin+capabilities

>Due to technical limitations, Obsidian cannot reliably restrict plugins to specific permissions or access levels. This means that plugins will inherit Obsidian's access levels. As a result, consider the following examples of what community plugins can do:

    Community plugins can access files on your computer.
    Community plugins can connect to internet.
    Community plugins can install additional programs.

Obsidian has no protection at all. Installing a plugin gives it full access to your computer.

This was only a matter of time, and honestly I think it's inexcusably negligent that they shipped a plugin system like this at all since about 2010 (or arguably much earlier).

pointlessone•1h ago
It does give full access but Obsidian does tell you that. Community plugins are not enabled by default, you have to enable them manually. Same happens with a shared vault: once you get it you still have to manually enable plugins. So far no one managed to sneak in a plugin completely unnoticed.
Groxx•50m ago
"Hey users: don't do insecure things. Here's a button to do cool insecure things!" is not a plugin security model.
kid64•46m ago
That's horse hockey. Obsidian is not a usable system without community plugins.

Folks will reply "but I use it every day without plugins".

That position disregards software usability as a formal discipline, along with decades of UX research and standards.

ImPostingOnHN•43m ago
The attack here requires not just enabling community plugins, but also syncing the attacker's vault to your computer, and also separately enabling the synchronization of the attacker's plugins with yours.
kid64•34m ago
Yeah, but these attacks are possible without any of that complexity.
Loocid•31m ago
As one of those people that uses Obsidian without plugins, what plugins do you consider essential?
Barrin92•28m ago
I think that's especially important to point out because it reminded me of a blog post by Obsidian that also was discussed here[1], where they talked about reducing supply chain risk by not relying on dependencies, but people quickly pointed out that this is only possible because users depend so heavily on extensions. Just look at that top comment and here we are now.

This combination of software relying on third parties without security seems to be untenable. Personally I've gotten rid of just about as many extensions as I can anywhere and switched to batteries included software.

[1]https://news.ycombinator.com/item?id=45307242

moron4hire•35m ago
A program one runs on one's computer can and should be able to do computer things. The alternative road you're advocating for ends in hardware attestation https://news.ycombinator.com/item?id=48086190
Paul-E•20m ago
Obsidian seems like a perfect candidate for a WASM/WASI based plugin system that would properly sandbox plugin code.
zhivota•1h ago
Even being social engineering, the design of the plugin system allowing this means the platform is completely unusable as a sharing tool. It's good to know but to me this is not "I need to remember to have these settings correct to use a shared Obsidian vault", this for is instead "never accept a shared Obsidian vault, demand a plaintext export".
kid64•36m ago
This is just the first detected and reported instance, in all likelyhood such attacks have been happening for some time. When will the fanatic userbsse finally admit that using Obsidian in any enterprise setting is just plain malpractice?

It takes 5 minutes in their Discord channel to see the founders are D&D nerds, not competent engineers. It was never meant for serious work.

TacticalCoder•33m ago
> It takes 5 minutes in their Discord channel to see the founders are D&D nerds, not competent engineers.

I know absolutely nothing about Obsidian but I'd expect quite a few competent engineers to also be D&D nerds no!?

Are you saying the two are mutually exclusive?

dspillett•25m ago
> the founders are D&D nerds, not competent engineers

The two are not mutually exclusive. What would you trust more than a nerd? A jock? A spod? An MBA?

Any evidence of other examples if bad engineering you can point to, or are your thoughts on the pluggin system and throwing shade at random groups of people all you've got?

[FYI: I know little of obsidian other than planning to look into it at some point as people I know use and like it. I stepped into this set of comments in case there was something useful I should be passing on to those people]

chillfox•4m ago
The attack relies on social engineering to get the victim to disable protections and could just as easily have happened with a plugin for any code editor.

Anyway, What I like about obsidian is that it can handle a truly huge amount of notes without slowing down, and the notes are just markdown files on disk, so there's no lock in. I have used evernote, ms one note and zoho notebook before, and had issues with all of them.

Hardware Attestation as Monopoly Enabler

https://grapheneos.social/@GrapheneOS/116550899908879585
783•ChuckMcM•6h ago•294 comments

Local AI needs to be the norm

https://unix.foo/posts/local-ai-needs-to-be-norm/
467•cylo•7h ago•228 comments

Incident Report: CVE-2024-YIKES

https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html
356•miniBill•6h ago•88 comments

Running local models on an M4 with 24GB memory

https://jola.dev/posts/running-local-models-on-m4
36•shintoist•1h ago•22 comments

Obsidian plugin was abused to deploy a remote access trojan

https://cyber.netsecops.io/articles/obsidian-plugin-abused-in-campaign-to-deploy-phantom-pulse-rat/
38•cmbailey•2h ago•18 comments

First tunnel element of the Fehmarnbelt Tunnel immersed

https://www.arup.com/en-us/news/first-fehmarnbelt-tunnel-element-lowered/
29•robin_reala•3d ago•7 comments

Why modern parents feel more sleep deprived than our ancestors did

https://www.bbc.com/future/article/20260508-parents-in-ancient-times-felt-less-sleep-deprived-wha...
66•1659447091•2h ago•47 comments

Ask HN: What are you working on? (May 2026)

115•david927•6h ago•407 comments

Guy Goma's Accidental BBC Interview Lives on After 20 Years

https://www.nytimes.com/2026/05/06/business/media/bbc-guy-goma-interview.html
28•nxobject•2d ago•8 comments

Traces Of Humanity

https://tracesofhumanity.org/hello-world/
123•alex77456•7h ago•19 comments

Maryland citizens hit with $2B power grid upgrade for out-of-state AI

https://www.tomshardware.com/tech-industry/artificial-intelligence/maryland-citizens-slapped-with...
107•lemonberry•3h ago•36 comments

I returned to AWS and was reminded why I left

http://fourlightyears.blogspot.com/2026/05/i-returned-to-aws-and-was-reminded-hard.html
641•andrewstuart•1d ago•466 comments

Eight More 8-bit Era Microprocessors (2024)

https://thechipletter.substack.com/p/eight-more-8-bit-era-microprocessors
45•klelatti•2d ago•12 comments

PS3 Emulator Devs Politely Ask That People Stop Flooding It with AI PRs

https://kotaku.com/playstation-3-emulator-devs-politely-ask-that-people-stop-flooding-it-with-ai-...
19•stalfosknight•45m ago•3 comments

The people preserving the scientific practice of bird banding

https://thenarwhal.ca/bird-banding-ontario/
24•bookofjoe•3d ago•0 comments

The locals don't know

https://www.quarter--mile.com/The-Locals-Dont-Know
90•herbertl•8h ago•62 comments

James Schuyler's Genius

https://yalereview.org/article/james-schuylers-genius
4•Thevet•1d ago•0 comments

Lakebase architecture delivers faster Postgres writes

https://www.databricks.com/blog/how-lakebase-architecture-delivers-5x-faster-postgres-writes
88•sp_from_db•2d ago•25 comments

Stop MitM on the first SSH connection, on any VPS or cloud provider

https://www.joachimschipper.nl/Stop%20MITM%20on%20the%20first%20SSH%20connection,%20on%20any%20VP...
68•JoachimSchipper•2d ago•41 comments

Idempotency is easy until the second request is different

https://blog.dochia.dev/blog/idempotency/
274•ludovicianul•3d ago•174 comments

What's a mathematician to do? (2010)

https://mathoverflow.net/questions/43690/whats-a-mathematician-to-do
144•ipnon•12h ago•72 comments

Louis Rossmann offers to pay legal fees for a threatened OrcaSlicer developer

https://www.tomshardware.com/3d-printing/louis-rossmann-tells-3d-printer-maker-bambu-lab-to-go-bl...
453•iancmceachern•9h ago•242 comments

Show HN: An index of indie web/blog indexes

https://theindex.fyi
91•rocketpastsix•11h ago•28 comments

Walking slower? Your ears, not your knees, might be the problem

https://www.wsj.com/health/wellness/hearing-loss-walking-speed-iphone-study-c53c482a
81•marc__1•1d ago•60 comments

Think Linear Algebra (2023)

https://allendowney.github.io/ThinkLinearAlgebra/index.html
153•tamnd•14h ago•17 comments

Task Paralysis and AI

https://g5t.de/articles/20260510-task-paralysis-and-ai/index.html
189•MrGilbert•18h ago•104 comments

Space Cadet Pinball on Linux

https://brennan.io/2026/05/09/pinball-and-escrow/
310•jandeboevrie•13h ago•102 comments

YC's Biggest Scandals

https://ycombinator.fyi/
222•laserduck•7h ago•78 comments

9 Mothers (YC P26) Is Hiring

https://jobs.ashbyhq.com/9-mothers?utm_source=x8pZ4B3P3Q
1•ukd1•12h ago

Spain has become one of Europe’s cheapest power markets

https://janrosenow.substack.com/p/spain-just-became-one-of-europes
139•marc__1•7h ago•112 comments