17 ms·
Obsidian plugin was abused to deploy a remote access trojan
- _qib3 5mo agoThis is becoming a bit of an epidemic. Not every attack or exploit (and especially not a social engineering one) needs a name out of Metal Gear or a website.
- Analemma_ 5mo agoWhen Heartbleed happened and they gave it a cool name and a fancy dedicated website, it was neat and probably necessary for that bug but I immediately had a sinking feeling that from then on every 2-bit security consultant trying to get free publicity would follow that playbook for nothingburger vulnerabilities, which is exactly what happened.
- slowmover 5mo ago> The victim is prompted to enable the "Installed community plugins" synchronization feature. Obsidian has the proper protections in place to prevent this type of attack, and the victims are being convinced to ignore them. This is just a successful social engineering event. I hate to see Obsidian dragged down by this headline, since this attack is not exploiting a vulnerability in it or its plugin system.
- cmbailey 5mo agoRight, I'm a heavy Obsidian user myself, and love it. I think the value of this disclosure is more in spreading awareness about plugins, and demonstrating the vector. Where less sophisticated users may think, "Oh, this is just a collection of markdown files. I don't need to be too worried about malicious code."
- Groxx 5mo agoEhm. No? https://obsidian.md/help/plugin-security#Plugin+capabilities https://obsidian.md/help/plugin-security#Plugin+capabilities >Due to technical limitations, Obsidian cannot reliably restrict plugins to specific permissions or access levels. This means that plugins will inherit Obsidian's access levels. As a result, consider the following examples of what community plugins can do: Community plugins can access files on your computer. Community plugins can connect to internet. Community plugins can install additional programs. Obsidian has no protection at all. Installing a plugin gives it full access to your computer. This was only a matter of time, and honestly I think it's inexcusably negligent that they shipped a plugin system like this at all since about 2010 (or arguably much earlier).
- pointlessone 5mo agoIt does give full access but Obsidian does tell you that. Community plugins are not enabled by default, you have to enable them manually. Same happens with a shared vault: once you get it you still have to manually enable plugins. So far no one managed to sneak in a plugin completely unnoticed.
- Groxx 5mo ago"Hey users: don't do insecure things. Here's a button to do cool insecure things!" is not a plugin security model.
- Ferret7446 5mo agoMeanwhile that is exactly what a lot of people here want for Android with side loaded apps
- eightys3v3n 5mo agoI'm not sure I agree or understand where you're coming from. Side-loaded Android apps are still bound by all the same permission restrictions as any app installed by the Play Store. The only difference is Google didn't review it (for what little good that does) and that I didn't get the app from Google. If I side-load a camera app, it still has to ask for camera privileges the same way any Play store app does. Is there something in your message I missed about how it relates to this article or is this just being uninformed about side-loading?
- Groxx 5mo agoSideloading bypasses nothing at all except Google's thumbs-up, Android's permission system doesn't work that way.
- kid64 5mo agoThat's horse hockey. Obsidian is not a usable system without community plugins. Folks will reply "but I use it every day without plugins". That position disregards software usability as a formal discipline, along with decades of UX research and standards.
- zhivota 5mo agoEven being social engineering, the design of the plugin system allowing this means the platform is completely unusable as a sharing tool. It's good to know but to me this is not "I need to remember to have these settings correct to use a shared Obsidian vault", this for is instead "never accept a shared Obsidian vault, demand a plaintext export".
- ValveFan6666 5mo agoWhat is this vibe-coded site? Why does it reiterate the same point 20 time? What are the actual plugins that I need to be on alert for? Chop chop, get to it.
- kid64 5mo agoThis is just the first detected and reported instance, in all likelyhood such attacks have been happening for some time. When will the fanatic userbsse finally admit that using Obsidian in any enterprise setting is just plain malpractice? It takes 5 minutes in their Discord channel to see the founders are D&D nerds, not competent engineers. It was never meant for serious work.
- TacticalCoder 5mo ago> It takes 5 minutes in their Discord channel to see the founders are D&D nerds, not competent engineers. I know absolutely nothing about Obsidian but I'd expect quite a few competent engineers to also be D&D nerds no!? Are you saying the two are mutually exclusive?
- dspillett 5mo ago> the founders are D&D nerds, not competent engineers The two are not mutually exclusive. What would you trust more than a nerd? A jock? A spod? An MBA? Any evidence of other examples if bad engineering you can point to, or are your thoughts on the pluggin system and throwing shade at random groups of people all you've got? [FYI: I know little of obsidian other than planning to look into it at some point as people I know use and like it. I stepped into this set of comments in case there was something useful I should be passing on to those people]
- chillfox 5mo agoThe attack relies on social engineering to get the victim to disable protections and could just as easily have happened with a plugin for any code editor. Anyway, What I like about obsidian is that it can handle a truly huge amount of notes without slowing down, and the notes are just markdown files on disk, so there's no lock in. I have used evernote, ms one note and zoho notebook before, and had issues with all of them.
- hresvelgr 5mo agoAm I the only one who thinks Obsidian is perfect without plugins? Half the reason I switched to it from Anytype was that it was rather spartan in its offerings. If they announced tomorrow they would ban plugins, I would not care.
- CGamesPlay 5mo agoI'm also switching back to Obsidian after a few-year stint on Anytype, and the Notebook Navigator plugin is the only one I have installed. This is (I assume) a UI-only plugin, which shouldn't need access to external network or processes, so a quite good candidate for sandboxed plugins.
- coffeefirst 5mo agoThat’s basically how I’m using it since I got wary about how the community plugins were being vetted. Core plugins and settings cover a lot. There’s one or two things I miss, but not enough to fork and review them myself so it’s clearly not essential.
- wiseowise 5mo agoThis. I only use official Obsidian plugins. Security + not depending on OSS maintainer are the main reasons.
- wiether 5mo agoI wouldn't say "perfect", but to me it's clear that adding plugins could only make it worse, even without considering the security issues. What I want from Obsidian is something that "just works". Adding third-party plugin would break this immediately since the plugins can either be straight up buggy, create conflicts with each other or simply become incompatible with new Obsidian releases. And what I've seen from the community, with people having dozens of plugins installed, is giving me nightmares. I can see why some would feel the appeal of plugins, and adding two or three can be fine, as long as you do your due diligence. Otherwise it's straight shooting you in the foot.
- deleted 5mo ago[deleted]
- vetchzero 5mo agoObsidian does not have auto update for community plugins. The steps for updating them right now is checking for updates and then updating all or individually. A bad update to one of the popular plugins could compromise lot of systems.
- jjice 5mo agoI really like Obsidian. I use it every day and I don't use any community plugins because the permissions aren't up to snuff. I hope for a day where a plugin defines what it will need and that gets presented to me as a user. I have to imagine the Obsidian team is going to respond seriously to this and I look forward to seeing what they do. They have my full confidence. I'm surprised the system was initially designed as it is without those better permissions and sandboxing, though.
- deleted 5mo ago[deleted]
- BrissyCoder 5mo agoI started using it too when I got sick of using VS Code to look at md. Glad I never had the need to install any plug-ins! Very poor form on their part from what I can tell.
- lossyalgo 5mo agoJust wait until you want to create a simple table with ADD/SUM.
- badcryptobitch 5mo agoMy worse fear has materialized. This is why I've never used an external Obsidian plugin and only my own plugins. It was only a matter of time before some malicious code ended up in one.
- deleted 5mo ago[deleted]
- 3eb7988a1663 5mo agoBrother, we are vindicated! There are indeed many cool bits and blobs out there, but I am already trusting one entity to secure my private notes, no way I am taking a pinky-promise from extension XYZ to behave. (I actually use LogSeq, but same idea applies).
- kepano 5mo agoObsidian CEO here. There is a major update coming soon for plugin security. I think it will address many of the concerns people have raised in this thread. It's a hard problem but we are working on it. That said, the headline is misleading. This article is about a social engineering attack that requires the user to actively reject multiple safety warnings in Obsidian. As far as I know this is a proof of concept, I haven't seen any reports of users being affected by this attack.
- ibash 5mo agolol we told you plugins were insecure years ago. I distinctly remember getting flamed in your discord because I said that they had full disk access. Too little too late.
- stingraycharles 5mo agoThese types of problems usually only get fixed when it’s too late.
- cromka 5mo ago"Sorry we got caught" reactiveness.
- redsocksfan45 5mo ago[dead]
- yard2010 5mo agoLol it's a social engineering attack. What are you talking about. Don't run programs you don't trust, especially when being asked to do so by strangers on the line.
- enoch2090 5mo agoYou better delete all third-party applications for they are having full disk access.
- dsp_person 5mo agoOne thing that bugged me when I made a community plugin was that you have to attach non-git-controlled files to the release (e.g. main.js). To check if any community plugin is safe, it seems like you'd have to not only review the code on github, but also analyze the github release files to be sure nothing malicious packed in there. Maybe I'm misunderstanding something about the process, I'd appreciate if anyone could confirm or explain otherwise.
- kepano 5mo agoThe recommended way to do this is via artifact attestation: https://docs.github.com/en/actions/how-tos/secure-your-work/use-artifact-attestations/use-artifact-attestations https://docs.github.com/en/actions/how-tos/secure-your-work/...
- dsp_person 5mo agoThanks that's interesting. The docs are aimed at developers, but I'm curious about the use case for the end user. So would a user have to do some kind of `gh attestation verify PATH/TO/YOUR/BUILD/ARTIFACT-BINARY ...`? (assuming the plugin dev provides an sbom?)
- kepano 5mo agoIn the near term artifact attestation will be visible to users in the directory, and part of the overall scorecard of a plugin.
- eviks 5mo agoWhat are the reasons behind the fact that almost all of these plugin systems are so poorly engineered? Is it too much work (ie, there are no good plugin development frameworks that already enable proper isolation/permission capabilities) or "simply" a widespread lack of knowledge of what is needed, so devs learn only after their own system has been abused? Both? Something else?
- stingraycharles 5mo agoYou’ll need to define the security framework and building blocks that all plugins may need, which takes time to design, implement, verify and maintain. Much easier to just skip that part. So yes, it’s too much work (in the sense that you need to have a security-focused leadership that understands that this is a lot of work but the right thing to do).
- pilgrim0 5mo agoWeb stack plus lack of resources to architect the proper interfaces is my guess. These are software written in high level js frameworks, thus using poor dataflow patterns by default, mostly just following what is actually possible instead of employing intentional design, which would require going down some levels of abstraction and maintaining a custom fork of said frameworks. So they probably just architect plug-ins like you would instantiate a library passing a subset of the context the app uses. Basically the simplest workable thing possible. Although the disclosed hack does not mention any particular “vulnerability”. Plug-ins in obsidian are always in god mode, and the alleged hackers just tricked people in using them. Funny how an RCE waiting to happen behind a few popups is ultimately blamed on users. Shame on the developers.
- movpasd 5mo ago"Worse is better" remains relevant as ever. https://www.jwz.org/doc/worse-is-better.html https://www.jwz.org/doc/worse-is-better.html
- cechmaster 5mo agoeven chrome browser plugins have security issues similar to this case. there are billions of dollars and many smart developers working on it. It's similar to building an app store inside your app. For the Apple app store, they reduce malicious apps by being very strict who/what people can publish and it's behind a paywall.
- dbacar 5mo agoReading the content the problem does not start with a plugin in Obisidian store but rather with a malicious vault they lure you to open.
- brusselsprout 5mo agoI hope I'm speaking as a minority but when I first started using Obsidian the Youtube videos I watched encourage the usage of community plugins, even with these warnings I would enable the community plugins. You may very well have good actors that eventually turn bad for these plugins and users won't know. Maybe I just also have a higher personal risk appetite, but even as a dev and knowing these risks I would have enabled the community plugin option. Again, hope I'm just the minority here and not most user behaviour.
- goobatrooba 5mo agoOne issue seems to be also that there are means dead plugins, not updated for years but still available. Does that mean they are especially stable or just no longer maintained? I don't know but ili applied the same rule I would for FDroid or the play store - not to install anything that isn't actively maintained. Also I can't tell how to prevent plugin updates. As long as you rely on a known safe version I guess there is never any real risk.
- nothinkjustai 5mo agoI think it’s fundamentally wrong to base your plugin architecture on running user code in the same space as the application. The proper way is to evaluate plugin scripts in an interpreter running in the application, where you expose functionality through functions and state exposed to the script runtime. This means you can A) sandbox everything and B) check for things like permissions or even request permissions at runtime. It’s harder if you use a language like JavaScript for the application since you essentially have a runtime inside a runtime, but it’s possible to run something like Lua inside JS. Since I use an actually good language like Rust I have many good options for scripting, like Rhai. Lua is also a good option. Go also has multiple options including a couple good Lua libraries. These libraries tend to have performance comparable to Python which is more than enough for most plugins in most apps.
- geoffbp 5mo agoI use the plugin for Git, and the one for tasks. Hope those are safe!
- cechmaster 5mo agoYou are safe. The way this hack works is that someone online would contact you, share a obsidian valut with you, you open the vault, you download & install a plugin the hacker tells you to install to open the vault. It's all described in the article if you would like to read it.
- Daedren 5mo agoThe obsidian vault is to already have the chosen plugin pre-selected and is part of the social engineering effort, that's not the main problem. The issue is that this could happen to anyone who just searches the malicious plugin's name and installs it. Worse if it's a popular one that gets compromised.
- elric 5mo agoI run Obsidian with restricted capabilities: no network access, and no filesystem access outside its own directory. I only enable network access when updating plugins/themes. Same way I run any other application that could potentially execute untrusted code.
- yjftsjthsd-h 5mo agoCould you share how you're sandboxing it?
- coldtea 5mo agoObsidian sounds like a nightmare security wise in general.
- cybrox 5mo agoHow is it any worse than say, VSCode in this regard?
- wiseowise 5mo agoYet another reason to not install anything third-party made. Favor batteries, built-in functionality and reject “Unix philosophy” or whatever bullshit people use to ship incomplete software under guise of.
- silon42 5mo agoI'd ideally want Obsidian to be a distro package, including any good plugins. No plugins from the "store".
- poemxo 5mo agoHopefully this improves workflow for installing plugins offline. It's not bad already but it's not as good as the connected experience.
- sshine 5mo agoYou say Trojan. I say shiny horse statue.
- amipwndidunno 5mo agoWhy the hell doesn't the article say WHICH plugins were affected so users can know if they were likely affected?
- deafpolygon 5mo agoIt does. > It enables malicious versions of legitimate Obsidian plugins ('Shell Commands' and 'Hider') that are present in the shared vault.
- lossyalgo 5mo agoThanks! I also scanned the detailed article looking for which plugins were affected and wasn't able to find it. Came to the comments looking for a quicker answer.
- kepano 5mo agoThe specific plugins don't matter for this attack. The attack relies on the user accepting a shared vault and trusting the shared plugins. A shared vault can contain plugins that don't come from the official directory.
- tredre3 5mo agoBecause no plugin is affected. This isn't a supply chain attack. The headline is deliberately obtuse. Here's the breakdown: 1. Plugins are stored inside your vault. 2. If you open a vault from an untrusted source, it could contain custom/malicious plugins that will run things on your computer. 3. Then end.
- exceptione 5mo agoA long time ago I figured that "nasty Obsidian plugins" were not a matter of if, but when. So I did the (imho) only sensible thing, and run Obsidian in a sandbox (bwrap). By doing so, I also made sure it runs in a separate networking namespace. For now, I disallow any internet access. The amount of rage I see here is a bit strange, the whole attraction of Obsidian is that you can turn it into a Swiss army knife (that can hurt you too ofc). @kepano: you would greatly help me if you could force plugin authors to list the urls they want to access inside the manifest, then let the user per url decide if they want to enable it. I still see some stupid plugin authors download their assets from a CDN or a vague website, from deeply buried in their code. Making url depencies explicit helps firewall automation at a first step. Maybe you could revoke direct network access from plugins, but i am not too knowledgeable about Electron.
- jedimastert 5mo ago> So I did the (imho) only sensible thing, and run Obsidian in a sandbox (bwrap). By doing so, I also made sure it runs in a separate networking namespace. For now, I disallow any internet access. > The amount of rage I see here is a bit strange Serious question: do you think it is actually obvious and technically accessable to everyday people to have the thought "I should run this in a sandbox" and do it? Like no this is not some super elite haxxr tool, it's a text editor pretty explicitly advertised as being non-technical-person-friendly.
- soco 5mo agoI haven't seen the term haxx0r since... ages! How are they called nowadays?
- exceptione 5mo ago> Serious question: do you think it is actually obvious and technically accessable to everyday people to have the thought "I should run this in a sandbox" and do it? I meant the HN crowd ofc. I assume the non-technical obsidian user would not be present here. You have a point though that non-technical people are screwed, but they have always been. Their whole lives and biometrics rest on Google and Apple servers anayways, while a good part of their identity is being traded by non-scrupulous commercial predators under the veil of advertising purposes. They are so beyond f*cked that I did not include their concerns wrt Obsidian plugins.
- gejose 5mo agoLove Obsidian but I've previously commented about the security model for plugins here: https://news.ycombinator.com/item?id=45308131 https://news.ycombinator.com/item?id=45308131. TLDR: your entire vault (and possibly filesystem) is exposed to every single plugin you install. I really do think Obsidian needs 2 things to have any reasonable security: 1. It needs to be a lot more batteries-included. A user shouldn't need a plugin for basic functionality. 2. It needs a granular permission system, where each plugin should have to declare and prompt you to allow or reject specific permissions, just like on iOS and Android. The system should enforce that a plugin cannot bypass this.
- criddell 5mo ago> A user shouldn't need a plugin for basic functionality. What functionality are you thinking of? I just looked and I've never enabled community plugins. My Obsidian complaint is the opposite. I think its bloated well beyond the initial premise of a markdown editor over a directory of files. I think it was just about perfect right before the introduction of the Canvas feature.
- kepano 5mo ago> More batteries-included Can I ask, what basic functionality is Obsidian missing in 2026? (I work on the app)
- gejose 5mo agoHey kepano, really love the work you're doing! Here are some feature I wish existed in Obsidian without any plugins: * Dataview [1] (this is now solved with Bases, so I really appreciate that) * Folder Note [2] (I, and I assume many others come from Notion, and I wish this were a thing) * Recent files [3] * A built in calendar [4] * Link embeds [5] (or something to store previews for pasted links) * Waypoint [6], or something to create a table of contents These are just things I wish existed, but whether or not these are 'basic' can be debated. Ultimately I do wish there were a robust permission system for plugins so that personal functionality gaps can be plugged, but without compromising safety. References: [1] https://blacksmithgu.github.io/obsidian-dataview/ https://blacksmithgu.github.io/obsidian-dataview/ [2] https://github.com/xpgo/obsidian-folder-note-plugin https://github.com/xpgo/obsidian-folder-note-plugin [3] https://github.com/tgrosinger/recent-files-obsidian https://github.com/tgrosinger/recent-files-obsidian [4] https://github.com/liamcain/obsidian-calendar-plugin https://github.com/liamcain/obsidian-calendar-plugin [5] https://github.com/Seraphli/obsidian-link-embed https://github.com/Seraphli/obsidian-link-embed [6] https://github.com/IdreesInc/Waypoint https://github.com/IdreesInc/Waypoint
- nstart 5mo agoThis is a misleading headline. It makes it seem like another supply chain attack where some good plug-in was taken over and used to deliver malware. Thats not the case here. Victims are invited to collaborate on a synced vault which comes preloaded with a non official plug-in that delivers the rat. Very very different story
- deafpolygon 5mo agoWhat’s misleading? "Novel Campaign Abuses Obsidian Note-Taking App to Target Finance and Crypto Professionals with PHANTOMPULSE RAT” It’s novel (new), an abuse of Obsidian, specifically targeting a group of people.. and the RAT is embedded in the vault.
- kepano 5mo agoThe headline on HN is different: "Obsidian plugin was abused to deploy a remote access trojan". It's not a plugin that was abused, but the ability for shared vaults to contain plugins.
- deafpolygon 5mo agoIsn’t that nearly the same thing? It depends on the presence of a particular plugin which was abused to run remote commands.
- kepano 5mo agoNo. The attack does not depend on the presence of a specific plugin. The ones listed in the article are just the ones that were used in the POC. Any plugin could be modified by the attacker if the user trusts the attacker and accepts 1. the vault, 2. the shared plugins, 3. disables restricted mode.
- rahilb 5mo agoSeems like a nice place to plug my Mac app that syncs your obsidian tasks to Reminders.app: https://turquoisehexagon.co.uk/remindersync https://turquoisehexagon.co.uk/remindersync (for me the only thing obsidian is missing on a fresh install). It’s sandboxed; can’t make network connections and can only read the directory you select. I’m surprised Apple haven’t added OS level functionality to block network connections / folder access for non sandboxed apps, similar to running an un-notarised binary.
- theuniverseson 5mo ago[flagged]
- sneilan1 5mo agoThis is why I NEVER install any obsidian plugins - EVER. Obsidian itself is good. Obsidian plugins = security nightmare.
- HackerThemAll 5mo agoHow to say you haven't read the article without saying you haven't read the article...
- hereme888 5mo agoWhoever taught LLMs to design webpages to look like that? I find myself telling agents to specifically not design like that. It's so a distracting and unfocused
- ApolloFortyNine 5mo agoI don't know when Obsidian gathered the hate I'm seeing here, but 'bad plugins' is a failure mode of most everything that has plugins. Personally it feels similar to being mad at Windows if you were to install an exe someone emailed you and it turned out to be a virus. You can install bad chrome plugins, bad wow addons, basically anything that's purpose is to run user code can be used to run bad code. Personally I'm glad the _note taking app_ prioritized allowing for custom plugins over pushing back features so they could spend an extra year locking down user plugins. They can put some additional effort in but running unknown code will always be a risk.
- brazukadev 5mo agoThere is no architectural limitation that makes it impossible for a plugin to not have full filesystem access. The fact that creating a good plugin system is difficult does not give them a free pass to not implement a good one, it is a for profit company that has a considerable revenue.
- marknutter 5mo agohttps://plugin.observer https://plugin.observer would come in handy for this.
- Itoldmyselfso 5mo agoA very relevant article: "On the security of plugins" (in notes app) https://standardnotes.com/blog/on-the-security-of-plugins https://standardnotes.com/blog/on-the-security-of-plugins
- goobatrooba 5mo agoWhile not wrong I'm not sure the publisher is uninterested as they are a competitor. E.g. this is how they criticise obsidian - suggesting that a default location backup is somehow worse than default cloud sync is just very strange to me. Obsidian stores your data as a folder of plaintext files on your local computer. You are thus responsible for securing this folder and making it available on your other devices. This is particularly difficult on mobile platforms that lack access to a robust file system.
- philipdavis 5mo agoi tried very hard to find a plugin that was deploying a Trojan but couldn’t find any. It looks to be a POC report. The title is so misleading and terrifying