Live data from Hacker News

Obsidian plugin was abused to deploy a remote access trojan

cyber.netsecops.io

161–170 of 241 posts

Re: Obsidian plugin was abused to deploy a remote access trojan

#161

Am I the only one who thinks Obsidian is perfect without plugins? Half the reason I switched to it from Anytype was that it was rather spartan in its offerings. If they announced tomorrow they would ban plugins, I would not care.

I wouldn't say "perfect", but to me it's clear that adding plugins could only make it worse, even without considering the security issues. What I want from Obsidian is something that "just works". Adding third-party plugin would break this immediately since the plugins can either be straight up buggy, create conflicts with each other or simply become incompatible with new Obsidian releases. And what I've seen from th…

[deleted]

Re: Obsidian plugin was abused to deploy a remote access trojan

#162

Earlier quoted context omitted.

This is pearl clutching. This feels like a massive overreaction. If you don't want to use it because it's not open source, that's fine, but you're spreading a lot of snarky FUD about the creators. They are not making excuses, they stated clearly why open sourcing it is tangential to this problem at best, and they're not the only user to call out the hijacking of the thread. They have been quite clear about why they k…

That's your opinion. I respect your choices and your opinions. I speak for myself. This is the first time I've seen this company's CEO post somewhere. I really couldn't trust this software less. To be fair, when someone comes up with excuses for not making something open source, it comes off as dishonest. Be honest. Say that you want to keep it closed to keep control and make money. There's no need to say otherwise.…

Consider a quick search. I have answered this question many times over the years, e.g. https://x.com/kepano/status/1701359669791670416

If you look at my GitHub profile[1] you'll see that the majority of my time is spent on open source. But my priority is open sourcing the tools and libraries I would want if I were building an alternative to Obsidian (Defuddle, JSON Canvas, Web Clipper, Importer, Flexoki, etc) because I believe all software is ephemeral and that files matter more than apps[2].

Obsidian is a free app made by seven people. If we were purely financially-motivated there are many levers we could have pulled, e.g. adding feature gates, not allowing alternatives to our paid services into the official directory, etc. But as I wrote in the tweet linked above, I have spent decades making open source projects and those have never paid the bills. So yes, there is some financial motivation behind that decision.

[1]: https://github.com/kepano

[2]: https://stephango.com/file-over-app

Re: Obsidian plugin was abused to deploy a remote access trojan

#163

Earlier quoted context omitted.

This is pearl clutching. This feels like a massive overreaction. If you don't want to use it because it's not open source, that's fine, but you're spreading a lot of snarky FUD about the creators. They are not making excuses, they stated clearly why open sourcing it is tangential to this problem at best, and they're not the only user to call out the hijacking of the thread. They have been quite clear about why they k…

That's your opinion. I respect your choices and your opinions. I speak for myself. This is the first time I've seen this company's CEO post somewhere. I really couldn't trust this software less. To be fair, when someone comes up with excuses for not making something open source, it comes off as dishonest. Be honest. Say that you want to keep it closed to keep control and make money. There's no need to say otherwise.…

> when someone comes up with excuses for not making something open source

This is a wild take even coming from HN. Nobody needs an excuse to not make something open source.

This sort of entitlement does, and has done, far more damage to the OSS movement than anyone's "excuses" for not open sourcing their code. Full stop.

You can absolutely prefer open source software and choose not to trust closed-source apps. That’s all fair. But treating closed source itself as evidence of deception or impending betrayal is exactly the kind of ideological purity test that makes these conversations exhausting.

Re: Obsidian plugin was abused to deploy a remote access trojan

#164
This is a misleading headline. It makes it seem like another supply chain attack where some good plug-in was taken over and used to deliver malware. Thats not the case here. Victims are invited to collaborate on a synced vault which comes preloaded with a non official plug-in that delivers the rat. Very very different story

Re: Obsidian plugin was abused to deploy a remote access trojan

#165
post #129

Love Obsidian but I've previously commented about the security model for plugins here: https://news.ycombinator.com/item?id=45308131 . TLDR: your entire vault (and possibly filesystem) is exposed to every single plugin you install. I really do think Obsidian needs 2 things to have any reasonable security: 1. It needs to be a lot more batteries-included. A user shouldn't need a plugin for basic functionality. 2. It ne…

> More batteries-included

Can I ask, what basic functionality is Obsidian missing in 2026? (I work on the app)

Re: Obsidian plugin was abused to deploy a remote access trojan

#166
post #164

This is a misleading headline. It makes it seem like another supply chain attack where some good plug-in was taken over and used to deliver malware. Thats not the case here. Victims are invited to collaborate on a synced vault which comes preloaded with a non official plug-in that delivers the rat. Very very different story

What’s misleading?

"Novel Campaign Abuses Obsidian Note-Taking App to Target Finance and Crypto Professionals with PHANTOMPULSE RAT”

It’s novel (new), an abuse of Obsidian, specifically targeting a group of people.. and the RAT is embedded in the vault.

Re: Obsidian plugin was abused to deploy a remote access trojan

#167
post #165
post #129

Love Obsidian but I've previously commented about the security model for plugins here: https://news.ycombinator.com/item?id=45308131 . TLDR: your entire vault (and possibly filesystem) is exposed to every single plugin you install. I really do think Obsidian needs 2 things to have any reasonable security: 1. It needs to be a lot more batteries-included. A user shouldn't need a plugin for basic functionality. 2. It ne…

> More batteries-included Can I ask, what basic functionality is Obsidian missing in 2026? (I work on the app)

Hey kepano, really love the work you're doing!

Here are some feature I wish existed in Obsidian without any plugins:

* Dataview [1] (this is now solved with Bases, so I really appreciate that)

* Folder Note [2] (I, and I assume many others come from Notion, and I wish this were a thing)

* Recent files [3]

* A built in calendar [4]

* Link embeds [5] (or something to store previews for pasted links)

* Waypoint [6], or something to create a table of contents

These are just things I wish existed, but whether or not these are 'basic' can be debated. Ultimately I do wish there were a robust permission system for plugins so that personal functionality gaps can be plugged, but without compromising safety.

References: [1] https://blacksmithgu.github.io/obsidian-dataview/ [2] https://github.com/xpgo/obsidian-folder-note-plugin [3] https://github.com/tgrosinger/recent-files-obsidian [4] https://github.com/liamcain/obsidian-calendar-plugin [5] https://github.com/Seraphli/obsidian-link-embed [6] https://github.com/IdreesInc/Waypoint

Re: Obsidian plugin was abused to deploy a remote access trojan

#168
post #163

Earlier quoted context omitted.

That's your opinion. I respect your choices and your opinions. I speak for myself. This is the first time I've seen this company's CEO post somewhere. I really couldn't trust this software less. To be fair, when someone comes up with excuses for not making something open source, it comes off as dishonest. Be honest. Say that you want to keep it closed to keep control and make money. There's no need to say otherwise.…

> when someone comes up with excuses for not making something open source This is a wild take even coming from HN. Nobody needs an excuse to not make something open source. This sort of entitlement does, and has done, far more damage to the OSS movement than anyone's "excuses" for not open sourcing their code. Full stop. You can absolutely prefer open source software and choose not to trust closed-source apps. That’s…

You've got it backwards. It's the fact that long arguments were written against making it open source that have determined me to make that statement. You don't have to provide an argument for not making it open source. It's the fact that arguments were made against making it open source or at least source available.

The business model is obvious. Sell the sync service.

Either way, that's your opinion.

Re: Obsidian plugin was abused to deploy a remote access trojan

#169
post #164

This is a misleading headline. It makes it seem like another supply chain attack where some good plug-in was taken over and used to deliver malware. Thats not the case here. Victims are invited to collaborate on a synced vault which comes preloaded with a non official plug-in that delivers the rat. Very very different story

What’s misleading? "Novel Campaign Abuses Obsidian Note-Taking App to Target Finance and Crypto Professionals with PHANTOMPULSE RAT” It’s novel (new), an abuse of Obsidian, specifically targeting a group of people.. and the RAT is embedded in the vault.

The headline on HN is different: "Obsidian plugin was abused to deploy a remote access trojan". It's not a plugin that was abused, but the ability for shared vaults to contain plugins.

Re: Obsidian plugin was abused to deploy a remote access trojan

#170
post #162

Earlier quoted context omitted.

That's your opinion. I respect your choices and your opinions. I speak for myself. This is the first time I've seen this company's CEO post somewhere. I really couldn't trust this software less. To be fair, when someone comes up with excuses for not making something open source, it comes off as dishonest. Be honest. Say that you want to keep it closed to keep control and make money. There's no need to say otherwise.…

Consider a quick search. I have answered this question many times over the years, e.g. https://x.com/kepano/status/1701359669791670416 If you look at my GitHub profile[1] you'll see that the majority of my time is spent on open source. But my priority is open sourcing the tools and libraries I would want if I were building an alternative to Obsidian (Defuddle, JSON Canvas, Web Clipper, Importer, Flexoki, etc) because…

I've read your twitter post. That makes sense. I've read a blog post or some kind forum thread in which it was said that the maintenance of Obsidian as an open source project would be an issue and some other similar statements. This was a while ago.

Some are OK with the use of a closed source note taking app. Perhaps an enterprise version with a different feature set might be useful to companies.

For notes written on my own computer, I use open source software to write and handle the sync myself.

Post reply on HN