logo

Obsidian’s Shell Commands Plugin Turned Into Universal Malware Launcher

ID: 9eab475a-0738-5aa4-81dc-89806e496ed6

STIX ID: report--9eab475a-0738-5aa4-81dc-89806e496ed6

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-14

Author: Varshini

...
...

**Executive summary:** A threat actor ran a targeted campaign abusing Obsidian's community plugin sync to deliver separate Windows and macOS malware chains: a staged PowerShell loader that loads the PHANTOMPULSE RAT in memory on Windows, and a Base64/AppleScript dropper with LaunchAgent persistence and Telegram fallback on macOS. The attack relied on social engineering (LinkedIn-to-Telegram), trusted application behavior, and plugin configuration to evade allowlist defenses; recommended mitigations include restricting/plugin review, process monitoring for unusual child processes of Obsidian, and network detection of unfamiliar domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.