Found this report via HackerNews. Attackers are getting victims to download Obsidian, enable community plugins, and use a shared “vault” to automatically download and execute scripts from a malicious plugin. End result is the phantompulse RAT on the system.
IOCs include Obsidian.exe spawning powershell.exe or cmd.exe on Windows or Obsidian spawning osascript on MacOS.
This smells like a poorly done AI-generated summary. Notice how three of the “references” at the bottom don’t even link to valid webpages. The STIX file download also has no actual IOCs in it. (The STIX file also describes this article as an “Original threat intelligence article”, which is just laughable.)