Obsidian plugin was abused to deploy a remote access trojan | Hacker News
TL;DR AI
2 min readKey summary
A malicious Obsidian community plugin was used to deliver a remote access trojan.
The Hacker News discussion split over whether this was social engineering or a product security failure.
Critics pointed to Obsidian’s broad plugin permissions and lack of sandboxing as the real risk.
The incident highlights how trusted third-party extensions can become a malware delivery path.



