(…) the attacker must convince the target to manually toggle the community plugin

Not that hard, enabling this is one of the first things an Obsidian user does. Having a thriving community of addons means this is inevitable.

thehackernews.com/2026/04/o…