New Crypto Scam Uses Obsidian Plugins to Hijack Devices
-

Crypto users are being targeted by a sophisticated new scam that exploits the plugin system of Obsidian to install malware. According to researchers at Elastic Security Labs, attackers are using social engineering tactics on LinkedIn and Telegram to trick victims into accessing a shared “work vault” that secretly contains malicious plugins.Once victims open the vault and enable community plugins, the attack is triggered automatically—no suspicious downloads or obvious warnings required. The malware, named PHANTOMPULSE, can silently take control of the victim’s device, making it particularly dangerous for individuals managing crypto assets.
This attack highlights a growing trend: hackers are no longer relying solely on phishing links or fake websites. Instead, they are exploiting trusted tools and workflows, making scams harder to detect and more convincing for even experienced users.