Obsidian’s Shell Commands Plugin Turned Into Universal Malware Launcher
ID: 9eab475a-0738-5aa4-81dc-89806e496ed6
STIX ID: report--9eab475a-0738-5aa4-81dc-89806e496ed6
Feed Name: Cyber Press
**Executive summary:** A threat actor ran a targeted campaign abusing Obsidian's community plugin sync to deliver separate Windows and macOS malware chains: a staged PowerShell loader that loads the PHANTOMPULSE RAT in memory on Windows, and a Base64/AppleScript dropper with LaunchAgent persistence and Telegram fallback on macOS. The attack relied on social engineering (LinkedIn-to-Telegram), trusted application behavior, and plugin configuration to evade allowlist defenses; recommended mitigations include restricting/plugin review, process monitoring for unusual child processes of Obsidian, and network detection of unfamiliar domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
